Not Failing Securely ('Failing Open') in Harbor - #VU153999
Published: October 8, 2026 / Updated: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to have requests processed without a determined authentication mode.
The vulnerability exists due to failure to stop request processing after an authentication mode lookup error in Harbor core's request security middleware when reading the configured authentication mode fails. A remote attacker can send requests during such a failure to have requests processed without a determined authentication mode.