Server-Side Request Forgery (SSRF) in Harbor - #VU153998
Published: October 8, 2026 / Updated: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to send server-side requests to arbitrary hosts and disclose stored registry credentials.
The vulnerability exists due to insufficient validation of next-page URL destinations in the registry replication client when following pagination links returned by a remote registry. A remote attacker can supply a crafted pagination Link header that redirects listing requests with stored registry credentials to another host to send server-side requests to arbitrary hosts and disclose stored registry credentials.
Exploitation requires control over responses from a remote registry already configured by a system administrator for pull-based replication. Requests can reach internal addresses, including the cloud metadata endpoint at 169.254.169.254. Harbor does not return the responses to users; only system administrators can read any resulting errors in replication logs.