Server-Side Request Forgery (SSRF) in Harbor - #VU153993

 

Server-Side Request Forgery (SSRF) in Harbor - #VU153993

Published: October 8, 2026 / Updated: October 8, 2026


Vulnerability identifier: #VU153993
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access internal services and cloud metadata endpoints and disclose portions of their error responses.

The vulnerability exists due to insufficient validation of webhook destination addresses in Harbor's jobservice webhook delivery when processing webhook events. A remote user can configure an HTTP or Slack webhook targeting a loopback, private, or link-local address to access internal services and cloud metadata endpoints and disclose portions of their error responses.

Exploitation requires project administrator permissions and network connectivity from jobservice to the target. With the default Project Creation: Everyone setting, any registered user can create a project and become its administrator. Webhook delivery sends an HTTP POST; when the target returns an error status, its response body is recorded in webhook execution logs readable by project members.


Affected software

Harbor

Remediation

Install security update from vendor's website.

Harbor - addressed in versions 2.13.6, 2.14.5, 2.15.3

External References

Related Security Bulletins