Always-Incorrect Control Flow Implementation in Harbor - #VU153948

 

Always-Incorrect Control Flow Implementation in Harbor - #VU153948

Published: October 7, 2026 / Updated: October 8, 2026


Vulnerability identifier: #VU153948
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-670
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass tag immutability protections.

The vulnerability exists due to incomplete evaluation of repository and tag selectors in the immutable tag rule matcher when matching tags against rules containing multiple repository or tag selectors. A remote user can overwrite or delete tags matched only by ignored selectors to bypass tag immutability protections.

Overwriting a tag requires project push permission, while deleting it requires delete permission; exploitation does not grant additional project permissions. Rules created through the web UI are not affected because they store a single pattern per selector type. Rules created or edited through the API, Terraform, or other automation can contain multiple selectors.


Affected software

Harbor

Remediation

Install security update from vendor's website.

Harbor - addressed in versions 2.13.6, 2.14.5, 2.15.3

External References

Related Security Bulletins