Resource exhaustion in Harbor - #VU153949

 

Resource exhaustion in Harbor - #VU153949

Published: October 7, 2026 / Updated: October 8, 2026


Vulnerability identifier: #VU153949
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in Harbor jobservice when reading and transparently decompressing webhook error response bodies without a size limit. A remote user can configure a webhook to point to a controlled receiver that repeatedly returns specially crafted gzip-compressed error responses to cause a denial of service.

Exploitation requires the project admin role. With the default Project Creation: Everyone setting, any registered user can create a project and become its admin. Jobservice is shared across all projects and also runs replication, scanning, garbage collection and retention jobs.


Affected software

Harbor

Remediation

Install security update from vendor's website.

Harbor - addressed in versions 2.13.6, 2.14.5, 2.15.3

External References

Related Security Bulletins