Server-Side Request Forgery (SSRF) in Harbor - #VU153996

 

Server-Side Request Forgery (SSRF) in Harbor - #VU153996

Published: October 8, 2026 / Updated: October 8, 2026


Vulnerability identifier: #VU153996
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose blob contents and registry credentials and induce server-side requests to arbitrary hosts.

The vulnerability exists due to improper validation of upload Location headers in Harbor's remote registry blob upload handling when processing destination registry responses during push-based replication. A remote attacker can return a crafted Location header pointing to another host to disclose blob contents and registry credentials and induce server-side requests to arbitrary hosts.

Exploitation requires control over responses from a destination registry already configured by a system administrator. Internal addresses and the cloud metadata endpoint 169.254.169.254 can be targeted. The issue applies both with and without Copy by chunk enabled. Request responses are not returned to users; replication errors may appear in logs accessible only to system administrators.


Affected software

Harbor

Remediation

Install security update from vendor's website.

Harbor - addressed in versions 2.13.6, 2.14.5, 2.15.3

External References

Related Security Bulletins