harbor vulnerabilities
CVEs whose affected-version data names the harbor package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-92770Medium· 6.5PoCHarbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials
Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on the AccessCredential column to recover the scanner adapter…
▾ Twilightgoharbor · harborEPSS 0.33%via NVD
CVE-2026-4404Critical· 9.4Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
▾ Midnightlinuxfoundation · harborEPSS 0.49%via NVD