Path traversal in Harbor - #VU153944

 

Path traversal in Harbor - #VU153944

Published: October 7, 2026 / Updated: October 8, 2026


Vulnerability identifier: #VU153944
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose image metadata and modify or delete tags and manifests across projects without the required repository permissions.

The vulnerability exists due to path traversal in the registry manifest endpoints when checking permissions against raw request paths before resolving parent-directory segments. A remote user can send crafted registry requests containing parent-directory segments to disclose image metadata and modify or delete tags and manifests across projects without the required repository permissions.

Changing or deleting content requires push access to at least one project. Unauthenticated manifest reads are also possible when the instance has at least one public project.


Affected software

Harbor

Remediation

Install security update from vendor's website.

Harbor - addressed in versions 2.13.6, 2.14.5, 2.15.3

External References

Related Security Bulletins