Reliance on Untrusted Inputs in a Security Decision in Harbor - #VU153997
Published: October 8, 2026 / Updated: October 8, 2026
Vulnerability details
The vulnerability allows a remote user to bypass vulnerability and content-trust pull policies and pull vulnerable or unsigned images.
The vulnerability exists due to reliance on untrusted input in a security decision in Harbor's image pull policy enforcement when handling image pull requests. A remote user can set the client-controlled User-Agent header to contain cosign or notation to bypass vulnerability and content-trust pull policies and pull vulnerable or unsigned images.
Exploitation requires push permission on the target project and at least one of these policies to be enabled. Accounts with only pull permission cannot bypass these policies.