Where
-Infinity
0

go/github.com/goharbor/harborUser permission validation failure and disclosure of P2P preheat execution logs

Risk 45
Severity
7.7
First published (updated )

go/github.com/goharbor/harborHarbor fails to validate the user permissions when updating project configurations

Risk 41
Severity
6.4
First published (updated )

go/github.com/goharbor/harborSQL Injection in Harbor scan log API

Risk 41
Severity
5.5
First published (updated )

go/github.com/goharbor/harborHarbor Open Redirect URL

Risk 39
Severity
6.1
First published (updated )

linuxfoundation HarborTiming attack risk in Harbor

Risk 46
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

linuxfoundation HarborAn access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private ima…

Risk 43
Severity
7.5
First published (updated )

go/github.com/goharbor/harborHarbor fails to validate the user permissions when updating a robot account

Risk 41
Severity
6.4
First published (updated )

go/github.com/goharbor/harborHarbor fails to validate the user permissions when updating tag immutability policies

Risk 45
Severity
7.7
First published (updated )

go/github.com/goharbor/harborHarbor fails to validate user permissions while Viewing, updating and deleting Webhook policies

Risk 45
Severity
7.7
First published (updated )

go/github.com/goharbor/harborHarbor fails to validate the user permissions when updating tag retention policies

Risk 45
Severity
7.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/goharbor/harborHarbor fails to validate the user permissions when reading and updating job execution logs through the P2P preheat execution logs

Risk 54
Severity
7.4
First published (updated )

linuxfoundation HarborCloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumerat…

Risk 27
Severity
5.3
First published (updated )

linuxfoundation HarborIn Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauth…

Risk 27
Severity
5.3
First published (updated )

go/github.com/goharbor/harborHarbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.

Risk 23
Severity
4.3
First published (updated )

linuxfoundation HarborSSRF

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

linuxfoundation HarborCloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnera…

Risk 79
Severity
8.8
First published (updated )

go/github.com/goharbor/harborSQL Injection

Risk 69
Severity
7.2
First published (updated )

linuxfoundation HarborSQL Injection

Risk 30
Severity
4.9
First published (updated )

go/github.com/goharbor/harborCSRF

Risk 80
Severity
8.8
First published (updated )

linuxfoundation HarborA User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This en…

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

linuxfoundation HarborHarbor API has a Broken Access Control vulnerability. The vulnerability allows project administrator…

Risk 43
Severity
7.5
First published (updated )

linuxfoundation Harborcore/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via t…

Risk 39
Severity
6.5
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203