VendorsLinux Foundationharborany version
Vulnerabilities

Linux Foundation The Linux Foundation Harbor any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2026-4404
Use of hard coded credentials in GoHarbor Harbor
Published 2026-03-23 · Analyzed
9.4EPSS 0.005
CVE-2019-19023
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform.
Published 2020-03-20 · Modified
8.8EPSS 0.016
CVE-2019-19025
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.
Published 2020-03-20 · Modified
8.8EPSS 0.010
CVE-2017-17697
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.
Published 2017-12-15 · Modified
8.6EPSS 0.014
CVE-2022-31670
Harbor fails to validate the user permissions when updating tag retention policies
Published 2024-11-14 · Analyzed
7.7EPSS 0.005
CVE-2022-31666
Harbor fails to validate user permissions while Viewing, updating and deleting Webhook policies
Published 2024-11-14 · Analyzed
7.7EPSS 0.005
CVE-2022-31669
Harbor fails to validate the user permissions when updating tag immutability policies
Published 2024-11-14 · Analyzed
7.7EPSS 0.004
CVE-2022-31668
User permission validation failure and disclosure of P2P preheat execution logs
Published 2024-11-14 · Analyzed
7.7EPSS 0.003
CVE-2022-46463
An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."
Published 2023-01-12 · Modified
7.5EPSS 0.062
CVE-2019-16919
Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The Harbor API did not enforce the proper project permissions and project scope on the API request to create a new robot account.
Published 2019-10-18 · Modified
7.5EPSS 0.017
CVE-2022-31671
Harbor fails to validate the user permissions when reading and updating job execution logs through the P2P preheat execution logs
Published 2024-11-14 · Analyzed
7.4EPSS 0.005
CVE-2019-19029
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.
Published 2020-03-20 · Modified
7.2EPSS 0.021
CVE-2023-20902
Timing attack risk in Harbor
Published 2023-11-09 · Modified
6.5EPSS 0.004
CVE-2022-31667
Harbor fails to validate the user permissions when updating a robot account
Published 2024-11-14 · Analyzed
6.4EPSS 0.005
CVE-2024-22278
Harbor fails to validate the user permissions when updating project configurations
Published 2024-08-02 · Modified
6.4EPSS 0.004
CVE-2024-22244
Harbor Open Redirect URL
Published 2024-06-10 · Analyzed
6.1EPSS 0.004
CVE-2024-22261
SQL Injection in Harbor scan log API
Published 2024-06-10 · Analyzed
5.5EPSS 0.004
CVE-2019-19030
Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.
Published 2022-12-26 · Modified
5.3EPSS 0.019
CVE-2020-29662
In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.
Published 2021-02-02 · Modified
5.3EPSS 0.007
CVE-2019-19026
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.
Published 2020-03-20 · Modified
4.9EPSS 0.014
CVE-2020-13788
Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
Published 2020-07-15 · Modified
4.3EPSS 0.013
CVE-2020-13794
Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.
Published 2020-09-29 · Modified
4.3EPSS 0.013
CVE-2019-3990
A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed to be restricted to administrators. This restriction is able to be bypassed and information can be obtained about registered users can be obtained via the "search" functionality.
Published 2019-12-03 · Modified
4.3EPSS 0.010