Reliance on Untrusted Inputs in a Security Decision in Harbor - #VU153997

 

Reliance on Untrusted Inputs in a Security Decision in Harbor - #VU153997

Published: October 8, 2026 / Updated: October 8, 2026


Vulnerability identifier: #VU153997
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-807
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass vulnerability and content-trust pull policies and pull vulnerable or unsigned images.

The vulnerability exists due to reliance on untrusted input in a security decision in Harbor's image pull policy enforcement when handling image pull requests. A remote user can set the client-controlled User-Agent header to contain cosign or notation to bypass vulnerability and content-trust pull policies and pull vulnerable or unsigned images.

Exploitation requires push permission on the target project and at least one of these policies to be enabled. Accounts with only pull permission cannot bypass these policies.


Affected software

Harbor

Remediation

Install security update from vendor's website.

Harbor - addressed in versions 2.13.6, 2.14.5, 2.15.3

External References

Related Security Bulletins