Allocation of Resources Without Limits or Throttling in Harbor - #VU153995
Published: October 8, 2026 / Updated: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service through excessive memory consumption.
The vulnerability exists due to unrestricted response-body consumption in the jobservice scanner bearer authorization token request when reading a response from the token endpoint. A remote attacker can supply an arbitrarily large response from a malicious token endpoint to cause a denial of service through excessive memory consumption.
Exploitation requires a network position between jobservice and Harbor core. The token request also has no timeout.