Memory Growth Vulnerability in ORAS CLI by Oracle
CVE-2026-55588
6.5MEDIUM
What is CVE-2026-55588?
The ORAS CLI, a tool for managing artifacts in OCI registries, is vulnerable due to a flaw in its recursive referrer traversal mechanism. Versions up to and including 1.3.2 do not properly track visited descriptors, creating a risk of unbounded recursion when interacting with malicious OCI registries that present cyclic referrer graphs. This can lead to excessive CPU and memory usage, potentially hanging automation or CI/CD workflows that rely on the 'oras discover,' 'oras backup,' and 'oras restore' operations. Users are advised to update to version 1.3.3 or higher to mitigate this risk.
Affected Version(s)
oras < 1.3.3
