Always-Incorrect Control Flow Implementation in Harbor - #VU153948
Published: October 7, 2026 / Updated: October 8, 2026
Vulnerability details
The vulnerability allows a remote user to bypass tag immutability protections.
The vulnerability exists due to incomplete evaluation of repository and tag selectors in the immutable tag rule matcher when matching tags against rules containing multiple repository or tag selectors. A remote user can overwrite or delete tags matched only by ignored selectors to bypass tag immutability protections.
Overwriting a tag requires project push permission, while deleting it requires delete permission; exploitation does not grant additional project permissions. Rules created through the web UI are not affected because they store a single pattern per selector type. Rules created or edited through the API, Terraform, or other automation can contain multiple selectors.