SB2026100860 - Multiple vulnerabilities in Harbor



SB2026100860 - Multiple vulnerabilities in Harbor

Published: October 8, 2026

Security Bulletin ID SB2026100860
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 15
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 13% Low 87%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 15 vulnerabilities.


1) Path traversal (CVE-ID: N/A)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose image metadata and modify or delete tags and manifests across projects without the required repository permissions.

The vulnerability exists due to path traversal in the registry manifest endpoints when checking permissions against raw request paths before resolving parent-directory segments. A remote user can send crafted registry requests containing parent-directory segments to disclose image metadata and modify or delete tags and manifests across projects without the required repository permissions.

Changing or deleting content requires push access to at least one project. Unauthenticated manifest reads are also possible when the instance has at least one public project.


2) Incorrect Privilege Assignment (CVE-ID: N/A)

CWE-ID: CWE-266 - Incorrect Privilege Assignment

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote privileged user to escalate privileges or revoke other users' administrator rights.

The vulnerability exists due to incorrect privilege assignment in Harbor's user-update functionality when processing user updates from system robot accounts. A remote privileged user can use a system robot token with the User: Update permission to set or remove any user's system administrator flag to escalate privileges or revoke other users' administrator rights.

Only a system administrator can create a system robot account with this permission.


3) Incorrect permission assignment for critical resource (CVE-ID: N/A)

CWE-ID: CWE-732 - Incorrect Permission Assignment for Critical Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote privileged user to read, modify, or delete resources across projects and take over project robot accounts, locking out their owners.

The vulnerability exists due to incorrect permission assignment in Harbor's system robot permission handling when processing project resource permissions with the cover all projects scope. A remote privileged user can exercise project read, update, or delete permissions as a global wildcard over resources inside every project, including changing robot permissions and resetting their secrets, to read, modify, or delete resources across projects and take over project robot accounts, locking out their owners.

Exploitation requires possession of a system robot account's token with the affected scope and project resource permissions. Robot accounts scoped to specific projects are not affected.


4) Authorization bypass through user-controlled key (CVE-ID: N/A)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges and pull, push, and delete images in every project, including private projects.

The vulnerability exists due to authorization bypass through username-based inheritance of local system-administrator privileges in the Harbor registry API (/v2/) when processing HTTP basic authentication with auth-proxy tokens. A remote user can submit a request using an auth-proxy token for an identity whose username matches a local Harbor system administrator to escalate privileges and pull, push, and delete images in every project, including private projects.

Only deployments using auth_mode = http_auth are affected. The identity provider must authenticate the matching identity, even though the auth proxy does not grant it administrator rights. The Harbor web UI and REST API (/api/v2.0) are not affected.


5) Always-Incorrect Control Flow Implementation (CVE-ID: N/A)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass tag immutability protections.

The vulnerability exists due to incomplete evaluation of repository and tag selectors in the immutable tag rule matcher when matching tags against rules containing multiple repository or tag selectors. A remote user can overwrite or delete tags matched only by ignored selectors to bypass tag immutability protections.

Overwriting a tag requires project push permission, while deleting it requires delete permission; exploitation does not grant additional project permissions. Rules created through the web UI are not affected because they store a single pattern per selector type. Rules created or edited through the API, Terraform, or other automation can contain multiple selectors.


6) Resource exhaustion (CVE-ID: N/A)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in Harbor jobservice when reading and transparently decompressing webhook error response bodies without a size limit. A remote user can configure a webhook to point to a controlled receiver that repeatedly returns specially crafted gzip-compressed error responses to cause a denial of service.

Exploitation requires the project admin role. With the default Project Creation: Everyone setting, any registered user can create a project and become its admin. Jobservice is shared across all projects and also runs replication, scanning, garbage collection and retention jobs.


7) Information disclosure (CVE-ID: N/A)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose scanner credentials.

The vulnerability exists due to a missing restriction on filtering sensitive credential values in scanner_registration.access_cred when handling scanner candidate list requests. A remote user can send repeated queries using the access_cred filter in the q parameter and observe whether a scanner is returned to disclose scanner credentials.

The endpoint requires the Project Admin role or a robot account granted scanner create permission on a project. Recovering a usable credential requires a scanner registration with authentication configured and a credential stored in plain text. Scanner registrations are global and can serve the entire Harbor instance. Registry contents and Harbor accounts are not exposed.


8) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N]


The vulnerability allows a remote user to access internal services and cloud metadata endpoints and disclose portions of their error responses.

The vulnerability exists due to insufficient validation of webhook destination addresses in Harbor's jobservice webhook delivery when processing webhook events. A remote user can configure an HTTP or Slack webhook targeting a loopback, private, or link-local address to access internal services and cloud metadata endpoints and disclose portions of their error responses.

Exploitation requires project administrator permissions and network connectivity from jobservice to the target. With the default Project Creation: Everyone setting, any registered user can create a project and become its administrator. Webhook delivery sends an HTTP POST; when the target returns an error status, its response body is recorded in webhook execution logs readable by project members.


9) Improper Certificate Validation (CVE-ID: N/A)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to capture temporary scan robot account credentials.

The vulnerability exists due to improper certificate validation in the jobservice bearer authorization token request when requesting a registry token from Harbor core over HTTPS for a scanner using bearer authorization. A remote attacker can intercept traffic between jobservice and Harbor core and present an arbitrary certificate to capture temporary scan robot account credentials.

Exploitation requires a network position between jobservice and Harbor core. The temporary robot account can read the project being scanned until the scan finishes and Harbor deletes the account.


10) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service through excessive memory consumption.

The vulnerability exists due to unrestricted response-body consumption in the jobservice scanner bearer authorization token request when reading a response from the token endpoint. A remote attacker can supply an arbitrarily large response from a malicious token endpoint to cause a denial of service through excessive memory consumption.

Exploitation requires a network position between jobservice and Harbor core. The token request also has no timeout.


11) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose blob contents and registry credentials and induce server-side requests to arbitrary hosts.

The vulnerability exists due to improper validation of upload Location headers in Harbor's remote registry blob upload handling when processing destination registry responses during push-based replication. A remote attacker can return a crafted Location header pointing to another host to disclose blob contents and registry credentials and induce server-side requests to arbitrary hosts.

Exploitation requires control over responses from a destination registry already configured by a system administrator. Internal addresses and the cloud metadata endpoint 169.254.169.254 can be targeted. The issue applies both with and without Copy by chunk enabled. Request responses are not returned to users; replication errors may appear in logs accessible only to system administrators.


12) Reliance on Untrusted Inputs in a Security Decision (CVE-ID: N/A)

CWE-ID: CWE-807 - Reliance on Untrusted Inputs in a Security Decision

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass vulnerability and content-trust pull policies and pull vulnerable or unsigned images.

The vulnerability exists due to reliance on untrusted input in a security decision in Harbor's image pull policy enforcement when handling image pull requests. A remote user can set the client-controlled User-Agent header to contain cosign or notation to bypass vulnerability and content-trust pull policies and pull vulnerable or unsigned images.

Exploitation requires push permission on the target project and at least one of these policies to be enabled. Accounts with only pull permission cannot bypass these policies.


13) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]


The vulnerability allows a remote attacker to send server-side requests to arbitrary hosts and disclose stored registry credentials.

The vulnerability exists due to insufficient validation of next-page URL destinations in the registry replication client when following pagination links returned by a remote registry. A remote attacker can supply a crafted pagination Link header that redirects listing requests with stored registry credentials to another host to send server-side requests to arbitrary hosts and disclose stored registry credentials.

Exploitation requires control over responses from a remote registry already configured by a system administrator for pull-based replication. Requests can reach internal addresses, including the cloud metadata endpoint at 169.254.169.254. Harbor does not return the responses to users; only system administrators can read any resulting errors in replication logs.


14) Not Failing Securely ('Failing Open') (CVE-ID: N/A)

CWE-ID: CWE-636 - Not Failing Securely (\'Failing Open\')

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to have requests processed without a determined authentication mode.

The vulnerability exists due to failure to stop request processing after an authentication mode lookup error in Harbor core's request security middleware when reading the configured authentication mode fails. A remote attacker can send requests during such a failure to have requests processed without a determined authentication mode.



15) Use-after-free (CVE-ID: CVE-2025-49844)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error. A remote user can use a specially crafted Lua script to manipulate the garbage collector and execute arbitrary code on the target system.


Remediation

Install update from vendor's website.