OSV 1.4.0 · github-reviewed · 修改于 2026-08-29 02:19
发布时间
2026-08-29 02:19
GitHub 审查时间
2026-08-29 02:19
NVD 发布时间
2026-08-26 05:17
源文件
advisories/github-reviewed/2026/08/GHSA-298f-872v-2rcx/GHSA-298f-872v-2rcx.json
A malicious OCI registry can return a cyclic referrer graph (e.g. A -> A or A -> B -> A). The ORAS CLI's recursive referrer traversal does not track visited descriptors, so a cycle causes unbounded recursion and memory growth — a client-side denial of service.
This affects oras discover (recursive referrer traversal) and the recursive referrer counting used by oras backup and oras restore. Because oras discover --depth defaults to 0 (unlimited), discover is affected out of the box.
Note: This advisory covers only the ORAS CLI (
oras.land/oras). The related Referrers API pagination loop in theoras-golibrary is tracked in a separate advisory on the oras-go repository.
In oras discover, recursive referrer traversal follows discovered referrers without maintaining a visited-descriptor set.
Simplified flow:
runDiscover
-> fetchAllReferrers(root)
-> registry.Referrers(root)
-> for each referrer:
fetchAllReferrers(referrer)
A malicious registry can create cyclic graphs such as:
A -> A
or
A -> B -> A
Because traversal does not track previously visited descriptors, recursion never reaches a terminating condition.
Similarly, the recursive counting logic (graph.RecursiveFindReferrers, used by the backup and restore workflows) accumulates descriptors without cycle detection, causing unbounded memory growth.
Create valid descriptors where:
referrers(A) = [A]
or:
referrers(A) = [B]
referrers(B) = [A]
Run:
oras discover attacker.local/repo@sha256:<A>
The recursive traversal continues indefinitely, causing unbounded recursion and eventual resource exhaustion.
A malicious OCI registry can trigger client-side denial of service against ORAS CLI users and automation.
Potential impacts include:
The issue does not enable arbitrary code execution, artifact substitution, or integrity bypass, but it can reliably prevent ORAS operations from completing when interacting with malicious registry metadata.
cmd/oras/root/discover.go — fetchAllReferrers threads a visited digest set; an already-traversed descriptor returns immediately, breaking cycles. Behavior is unchanged for valid (acyclic) referrer graphs.internal/graph/graph.go — RecursiveFindReferrers tracks visited descriptors by digest and only recurses into unseen referrers, so traversal terminates on a cyclic graph.