THREAT OPS › Threat News › [GHSA] GHSA-298f-872v-2rcx (low) — ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
[GHSA] GHSA-298f-872v-2rcx (low) — ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
GHSA-298f-872v-2rcx Severity: low CVE: CVE-2026-55588
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
### Summary
A malicious OCI registry can return a **cyclic referrer graph** (e.g. `A -> A` or `A -> B -> A`). The ORAS CLI's recursive referrer traversal does not track visited descriptors, so a cycle causes unbounded recursion and memory growth — a client
Indicators of compromise
- CVE-2026-55588cve
Original source: https://github.com/advisories/GHSA-298f-872v-2rcx