{"id":"ECHO-907e-3d79-47e5","upstream":["CVE-2026-85732","GHSA-h7vf-4x9w-h99v"],"severity":[],"modified":"2026-09-28T00:02:34.894Z","affected":[{"package":{"ecosystem":"Echo:Go","name":"oras.land/oras-go/v2","purl":"pkg:golang/oras.land/oras-go/v2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.2-1"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-85732"},{"type":"WEB","url":"https://github.com/advisories/GHSA-h7vf-4x9w-h99v"}]}