Goharbor

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-4404

    Use of hard coded credentials in GoHarbor Harbor

    Last Modified: Mar 25, 2026
    Published: Mar 23, 2026

    CVE-2025-30086

    CNCF Harbor 2.13.x before 2.13.1 and 2.12.x before 2.12.4 allows information disclosure by administrators who can exploit an ORM Leak present in the /api/v2.0/users endpoint to leak users' password hash and salt values. The q URL parameter allows a user to filter users by any column, and filter password=~ could be abused to leak out a user's password hash character by character. An attacker with administrator access could exploit this to leak highly sensitive information stored in the Harbor database. All endpoints that support the q URL parameter are vulnerable to this ORM leak attack.

    Last Modified: Apr 15, 2026
    Published: Jul 25, 2025

    CVE-2025-32019

    Harbor's repository description page allows for XSS

    Last Modified: Apr 15, 2026
    Published: Jul 23, 2025

    CVE-2022-31666

    Harbor fails to validate user permissions while Viewing, updating and deleting Webhook policies

    Last Modified: Jul 12, 2025
    Published: Nov 14, 2024
    Items Per Page
    Goharbor Vulnerabilities & Security CVEs | CVE-DB