goharbor has 6 CVEs on record between 2021 and 2026. 1 was published in the last 90 days. The median CVSS is 4.8 (medium). None have a confirmed exploitation report. Most affected products: github.com/goharbor/harbor (5), harbor (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.8
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Weakness classes
Products
- github.com/goharbor/harbor 5
- harbor 1
Worst active — by depth score
CVE-2026-92770Medium· 6.5Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials48CVE-2023-20902Medium· 5.9Harbor timing attack risk33CVE-2020-29662Medium· 5.3"catalog's registry v2 api exposed on unauthenticated path in Harbor"29CVE-2024-22244Medium· 4.3Open Redirect URL in Harbor24CVE-2020-13794Medium· 4.3Authenticated users can exploit an enumeration vulnerability in Harbor24
goharbor vulnerabilities
CVEs affecting goharbor, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-92770Medium· 6.5PoCHarbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials
Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on the AccessCredential column to recover the scanner adapter…
CVE-2024-22261Low· 2.7SQL Injection in Harbor scan log API
SQL Injection in Harbor scan log API
CVE-2024-22244Medium· 4.3Open Redirect URL in Harbor
Open Redirect URL in Harbor
CVE-2023-20902Medium· 5.9Harbor timing attack risk
Harbor timing attack risk
CVE-2020-29662Medium· 5.3"catalog's registry v2 api exposed on unauthenticated path in Harbor"
"catalog's registry v2 api exposed on unauthenticated path in Harbor"
CVE-2020-13794Medium· 4.3Authenticated users can exploit an enumeration vulnerability in Harbor
Authenticated users can exploit an enumeration vulnerability in Harbor