Launch Week Day 1: Announcing Security Design Review
go

github.com/goharbor/harbor

View on go registry
41 Total advisories
41 Vulnerabilities
0 Malware

Vulnerabilities

UNKNOWN
Go

GO-2026-4876

Harbor: LDAP password and OIDC secret are not redacted in the audit log

UNKNOWN
Go

GHSA-prh4-vhfh-24mj

Harbor: LDAP password and OIDC secret are not redacted in the audit log in github.com/goharbor/harbor

CRITICAL 9.4
Go

CVE-2026-4404

Harbor allows the use of the default password for web UI login

UNKNOWN
Go

CVE-2026-4404

Harbor allows the use of the default password for web UI login in github.com/goharbor/harbor

MEDIUM 5.3
Go

CVE-2020-29662

"catalog's registry v2 api exposed on unauthenticated path in Harbor"

MEDIUM 4.3
Go

CVE-2020-13794

Authenticated users can exploit an enumeration vulnerability in Harbor

MEDIUM 5.3
Go

CVE-2019-19030

Unauthenticated users can exploit an enumeration vulnerability in Harbor (CVE-2019-19030)

MEDIUM 5.9
Go

CVE-2023-20902

Harbor timing attack risk

LOW 2.7
Go

CVE-2024-22261

SQL Injection in Harbor scan log API

MEDIUM 4.3
Go

CVE-2024-22244

Open Redirect URL in Harbor

UNKNOWN
Go

CVE-2025-32019

Harbor repository description page has Cross-site Scripting vulnerability in github.com/goharbor/harbor

UNKNOWN
Go

CVE-2022-31668

Harbor fails to validate the user permissions when updating p2p preheat policies in github.com/goharbor/harbor

UNKNOWN
Go

CVE-2024-22261

SQL Injection in Harbor scan log API in github.com/goharbor/harbor

UNKNOWN
Go

CVE-2024-22244

Open Redirect URL in Harbor in github.com/goharbor/harbor

UNKNOWN
Go

CVE-2023-20902

Harbor timing attack risk in github.com/goharbor/harbor

UNKNOWN
Go

CVE-2019-19026

SQL Injection in Cloud Native Computing Foundation Harbor in github.com/goharbor/harbor

UNKNOWN
Go

CVE-2019-19025

Cross-site Request Forgery (CSRF) in Cloud Native Computing Foundation Harbor in github.com/goharbor/harbor

UNKNOWN
Go

CVE-2019-19029

SQL Injection in Cloud Native Computing Foundation Harbor in github.com/goharbor/harbor

UNKNOWN
Go

CVE-2020-13794

Authenticated users can exploit an enumeration vulnerability in Harbor in github.com/goharbor/harbor

UNKNOWN
Go

CVE-2019-19023

Privilege Escalation in Cloud Native Computing Foundation Harbor in github.com/goharbor/harbor

UNKNOWN
Go

CVE-2024-22278

Harbor fails to validate the user permissions when updating project configurations in github.com/goharbor/harbor

UNKNOWN
Go

CVE-2019-16097

Missing Authorization in Harbor in github.com/goharbor/harbor

UNKNOWN
Go

CVE-2020-29662

"catalog's registry v2 api exposed on unauthenticated path in Harbor" in github.com/goharbor/harbor

UNKNOWN
Go

CVE-2020-13788

Harbor is vulnerable to a limited Server-Side Request Forgery (SSRF) (CVE-2020-13788) in github.com/goharbor/harbor

UNKNOWN
Go

CVE-2019-19030

Unauthenticated users can exploit an enumeration vulnerability in Harbor (CVE-2019-19030) in github.com/goharbor/harbor

MEDIUM 5.0
Go

CVE-2022-31671

Harbor fails to validate the user permissions when reading job execution logs through the P2P preheat execution logs

HIGH 7.7
Go

CVE-2022-31666

Harbor fails to validate the user permissions when viewing Webhook policies

MEDIUM 4.1
Go

CVE-2025-32019

Harbor repository description page has Cross-site Scripting vulnerability

UNKNOWN
Go

CVE-2025-30086

Possible ORM Leak Vulnerability in the Harbor in github.com/goharbor/harbor

MEDIUM 4.9
Go

CVE-2025-30086

Possible ORM Leak Vulnerability in the Harbor

HIGH 7.4
Go

CVE-2022-31668

Harbor fails to validate the user permissions when updating p2p preheat policies

MEDIUM 6.4
Go

CVE-2022-31667

Harbor fails to validate the user permissions when updating a robot account

HIGH 7.7
Go

CVE-2022-31670

Harbor fails to validate the user permissions when updating tag retention policies

MEDIUM 6.4
Go

CVE-2022-31669

Harbor fails to validate the user permissions when updating tag immutability policies

MEDIUM 5.5
Go

CVE-2024-22278

Harbor fails to validate the user permissions when updating project configurations

HIGH 7.6
Go

CVE-2019-19025

Cross-site Request Forgery (CSRF) in Cloud Native Computing Foundation Harbor

HIGH 7.2
Go

CVE-2019-19029

SQL Injection in Cloud Native Computing Foundation Harbor

MEDIUM 6.5
Go

CVE-2019-16097

Missing Authorization in Harbor

MEDIUM 4.9
Go

CVE-2019-19026

SQL Injection in Cloud Native Computing Foundation Harbor

MEDIUM 4.4
Go

CVE-2020-13788

Harbor is vulnerable to a limited Server-Side Request Forgery (SSRF) (CVE-2020-13788)

CRITICAL 9.3
Go

CVE-2019-19023

Privilege Escalation in Cloud Native Computing Foundation Harbor

Ready to move

Start Securing

Free, no credit card | First findings in minutes