Server-Side Request Forgery (SSRF) in Harbor - #VU153993
Published: October 8, 2026 / Updated: October 8, 2026
Vulnerability details
The vulnerability allows a remote user to access internal services and cloud metadata endpoints and disclose portions of their error responses.
The vulnerability exists due to insufficient validation of webhook destination addresses in Harbor's jobservice webhook delivery when processing webhook events. A remote user can configure an HTTP or Slack webhook targeting a loopback, private, or link-local address to access internal services and cloud metadata endpoints and disclose portions of their error responses.
Exploitation requires project administrator permissions and network connectivity from jobservice to the target. With the default Project Creation: Everyone setting, any registered user can create a project and become its administrator. Webhook delivery sends an HTTP POST; when the target returns an error status, its response body is recorded in webhook execution logs readable by project members.