Server-Side Request Forgery (SSRF) in Harbor - #VU153996
Published: October 8, 2026 / Updated: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose blob contents and registry credentials and induce server-side requests to arbitrary hosts.
The vulnerability exists due to improper validation of upload Location headers in Harbor's remote registry blob upload handling when processing destination registry responses during push-based replication. A remote attacker can return a crafted Location header pointing to another host to disclose blob contents and registry credentials and induce server-side requests to arbitrary hosts.
Exploitation requires control over responses from a destination registry already configured by a system administrator. Internal addresses and the cloud metadata endpoint 169.254.169.254 can be targeted. The issue applies both with and without Copy by chunk enabled. Request responses are not returned to users; replication errors may appear in logs accessible only to system administrators.