CVE-2026-85731 | oras-project oras-go up to 2.6.1 Tar Extraction extractTarDirectory path traversal

SecurityVulns

A vulnerability classified as critical was found in oras-project oras-go up to 2.6.1. The impacted element is the function extractTarDirectory of the component Tar Extraction. Such manipulation leads to path traversal.

This vulnerability is listed as CVE-2026-85731. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.VulDB Recent EntriesRead More