<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Harbor (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/harbor.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/harbor-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Harbor (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:58 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-4404 – Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4404</guid>
    <pubDate>Mon, 23 Mar 2026 15:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4404</strong></p>
  <p>Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31671 – Harbor fails to validate user permissions when reading and updating job executio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31671</guid>
    <pubDate>Thu, 14 Nov 2024 12:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31671</strong></p>
  <p>Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying different job IDs, malicious authenticated users could read all the job logs stored in the Harbor database.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31670 – Harbor fails to validate the user permissions when updating tag retention polici...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31670</guid>
    <pubDate>Thu, 14 Nov 2024 12:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31670</strong></p>
  <p>Harbor fails to validate the user permissions when updating tag retention policies.   By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag retention policies configured in other projects.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31668 – Harbor fails to validate the user permissions when updating p2p preheat policies...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31668</guid>
    <pubDate>Thu, 14 Nov 2024 12:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31668</strong></p>
  <p>Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other projects.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31666 – Harbor fails to validate user permissions while deleting Webhook policies, allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31666</guid>
    <pubDate>Thu, 14 Nov 2024 12:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31666</strong></p>
  <p>Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users.  The attacker could modify Webhook policies configured in other projects.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-46463 – An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access pu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46463</guid>
    <pubDate>Fri, 13 Jan 2023 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-46463</strong></p>
  <p>An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19029 – Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19029</guid>
    <pubDate>Fri, 20 Mar 2020 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19029</strong></p>
  <p>Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19025 – Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19025</guid>
    <pubDate>Fri, 20 Mar 2020 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19025</strong></p>
  <p>Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19023 – Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privileg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19023</guid>
    <pubDate>Fri, 20 Mar 2020 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19023</strong></p>
  <p>Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16919 – Harbor API has a Broken Access Control vulnerability. The vulnerability allows p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16919</guid>
    <pubDate>Fri, 18 Oct 2019 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16919</strong></p>
  <p>Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The Harbor API did not enforce the proper project permissions and project scope on the API request to create a new robot account.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-17697 – The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-17697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-17697</guid>
    <pubDate>Fri, 15 Dec 2017 09:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-17697</strong></p>
  <p>The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17697">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
