Vulnerability Reportgoharbor/harbor-core:v2.14.3

goharbor/harbor-core:v2.14.3goharbor/harbor-core:v2.14.3-rc1
DIGESTsha256:a30e5a8be3d94b6485e7fdd4ed7fdf9e9724ee0a6d103b3804aacf6784ee358e

Executive Summary

Threat Score
75/100DANGEROUS
Reputation
RELIABLE

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could achieve remote code execution by sending a crafted TLS handshake (CVE-2026-2781). For the gRPC authorization bypass (CVE-2026-33186), deploying a validating interceptor that rejects malformed HTTP/2 paths fully mitigates that risk. No special configuration is required for the most critical vulnerability, making it widely exploitable.

Vulnerabilities

Vulnerability Log

126 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-2781HIGH8.33
nss-libs
3.78-11.ph5
fixed in 3.78-12.ph5
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-45186MEDIUM6.38
expat-libs
2.7.4-1.ph5
fixed in 2.8.1-1.ph5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-35172MEDIUM6.38
github.com/distribution/distribution
v2.8.2+incompatible
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34986MEDIUM6.38
github.com/go-jose/go-jose/v4
v4.0.5
fixed in 4.1.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39820MEDIUM6.38
stdlib
v1.24.13
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39836MEDIUM6.38
stdlib
v1.24.13
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33186MEDIUM6.18
google.golang.org/grpc
v1.69.4
fixed in 1.79.3
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39883MEDIUM5.95
go.opentelemetry.io/otel/sdk
v1.40.0
fixed in 1.43.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc
2.36-22.ph5
fixed in 2.36-23.ph5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-libs
2.36-22.ph5
fixed in 2.36-23.ph5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41888MEDIUM5.52
github.com/distribution/distribution
v2.8.2+incompatible
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-32282MEDIUM5.44
stdlib
v1.24.13
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM5.18
stdlib
v1.24.13
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-29181MEDIUM5.1
go.opentelemetry.io/otel
v1.40.0
fixed in 1.41.0
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-25679MEDIUM5.1
stdlib
v1.24.13
fixed in 1.25.8, 1.26.1
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32280MEDIUM5.1
stdlib
v1.24.13
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32281MEDIUM5.1
stdlib
v1.24.13
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-32283MEDIUM5.1
stdlib
v1.24.13
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-31790MEDIUM5.02
openssl-libs
3.0.18-2.ph5
fixed in 3.0.18-3.ph5
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42764MEDIUM5.02
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-31789MEDIUM5
openssl-libs
3.0.18-2.ph5
fixed in 3.0.18-3.ph5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32776MEDIUM4.67
expat-libs
2.7.4-1.ph5
fixed in 2.7.5-1.ph5
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-32777MEDIUM4.67
expat-libs
2.7.4-1.ph5
fixed in 2.7.5-1.ph5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32778MEDIUM4.67
expat-libs
2.7.4-1.ph5
fixed in 2.7.5-1.ph5
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.2.13-5.ph5
fixed in 1.3.2-1.ph5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-32288MEDIUM4.67
stdlib
v1.24.13
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
stdlib
v1.24.13
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.24.13
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc
2.36-22.ph5
fixed in 2.36-23.1.ph5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-libs
2.36-22.ph5
fixed in 2.36-23.1.ph5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
xz-libs
5.4.0-5.ph5
fixed in 5.4.0-6.ph5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc
2.36-22.ph5
fixed in 2.43-3.ph5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc
2.36-22.ph5
fixed in 2.43-3.ph5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-libs
2.36-22.ph5
fixed in 2.43-3.ph5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-libs
2.36-22.ph5
fixed in 2.43-3.ph5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-6276LOW3.82
curl
8.18.0-1.ph5
fixed in 8.19.0-2.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW3.82
curl-libs
8.18.0-1.ph5
fixed in 8.19.0-2.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW3.82
curl-libs
8.18.0-1.ph5
fixed in 8.19.0-2.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW3.77
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-1965LOW3.47
curl
8.18.0-1.ph5
fixed in 8.19.0-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-1965LOW3.47
curl-libs
8.18.0-1.ph5
fixed in 8.19.0-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-4438LOW3.4
glibc
2.36-22.ph5
fixed in 2.36-23.ph5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-libs
2.36-22.ph5
fixed in 2.36-23.ph5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-3784LOW3.31
curl
8.18.0-1.ph5
fixed in 8.19.0-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
curl
8.18.0-1.ph5
fixed in 8.19.0-2.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW3.31
curl
8.18.0-1.ph5
fixed in 8.19.0-2.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3784LOW3.31
curl-libs
8.18.0-1.ph5
fixed in 8.19.0-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
curl-libs
8.18.0-1.ph5
fixed in 8.19.0-2.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW3.31
curl-libs
8.18.0-1.ph5
fixed in 8.19.0-2.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW3.21
curl
8.18.0-1.ph5
fixed in 8.19.0-1.ph5
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW3.21
curl-libs
8.18.0-1.ph5
fixed in 8.19.0-1.ph5
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-34181LOW3.21
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42768LOW3.21
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-41080LOW3.15
expat-libs
2.7.4-1.ph5
fixed in 2.8.0-1.ph5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-31790LOW3.01
openssl
3.0.18-2.ph5
fixed in 3.0.18-3.ph5
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-42764LOW3.01
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW3.01
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW3.01
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW3.01
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
openssl
3.0.18-2.ph5
fixed in 3.0.18-3.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-41889LOW3
github.com/jackc/pgx/v4
v4.18.3
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-3783LOW2.91
curl
8.18.0-1.ph5
fixed in 8.19.0-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-3783LOW2.91
curl-libs
8.18.0-1.ph5
fixed in 8.19.0-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7383LOW2.8
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-70873LOW2.8
sqlite-libs
3.43.2-5.ph5
fixed in 3.43.2-6.ph5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-7598LOW2.78
libssh2
1.11.0-4.ph5
fixed in 1.11.1-3.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-32952LOW2.7
github.com/Azure/go-ntlmssp
v0.0.0-20221128193559-754e69321358
fixed in 0.1.1
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-4873LOW2.7
curl
8.18.0-1.ph5
fixed in 8.19.0-2.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
curl
8.18.0-1.ph5
fixed in 8.19.0-2.ph5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-7009LOW2.7
curl
8.18.0-1.ph5
fixed in 8.20.0-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
curl
8.18.0-1.ph5
fixed in 8.20.0-1.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4873LOW2.7
curl-libs
8.18.0-1.ph5
fixed in 8.19.0-2.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
curl-libs
8.18.0-1.ph5
fixed in 8.19.0-2.ph5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-7009LOW2.7
curl-libs
8.18.0-1.ph5
fixed in 8.20.0-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
curl-libs
8.18.0-1.ph5
fixed in 8.20.0-1.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW2.7
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-33540LOW2.63
github.com/distribution/distribution
v2.8.2+incompatible
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34180LOW2.55
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-28387LOW2.48
openssl
3.0.18-2.ph5
fixed in 3.0.18-3.ph5
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-28387LOW2.48
openssl-libs
3.0.18-2.ph5
fixed in 3.0.18-3.ph5
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW2.29
curl
8.18.0-1.ph5
fixed in 8.19.0-2.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-28388LOW2.29
openssl
3.0.18-2.ph5
fixed in 3.0.18-3.ph5
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-28389LOW2.29
openssl
3.0.18-2.ph5
fixed in 3.0.18-3.ph5
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-28390LOW2.29
openssl
3.0.18-2.ph5
fixed in 3.0.18-3.ph5
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.29
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-28388LOW2.29
openssl-libs
3.0.18-2.ph5
fixed in 3.0.18-3.ph5
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-28389LOW2.29
openssl-libs
3.0.18-2.ph5
fixed in 3.0.18-3.ph5
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-28390LOW2.29
openssl-libs
3.0.18-2.ph5
fixed in 3.0.18-3.ph5
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.29
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-32286LOW2.29
github.com/jackc/pgproto3/v2
v2.3.3
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-33811LOW2.29
stdlib
v1.24.13
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-33814LOW2.29
stdlib
v1.24.13
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-35206LOW2.24
helm.sh/helm/v3
v3.18.5
fixed in 3.20.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-27139LOW2.12
stdlib
v1.24.13
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW1.89
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69720NONE0
ncurses-libs
6.5-1.ph5
fixed in 6.5-2.ph5
0.4%
Theoretical Threat
Not Applicable
BDSA-2026-9096NONE0
curl
8.18.0-1.ph5
fixed in 8.20.0-1.ph5
Not Applicable
BDSA-2026-9096NONE0
curl-libs
8.18.0-1.ph5
fixed in 8.20.0-1.ph5
Not Applicable
BDSA-2026-9020NONE0
libssh2
1.11.0-4.ph5
fixed in 1.11.1-3.ph5
Not Applicable
CVE-2026-42765NONE0
openssl
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42765NONE0
openssl-libs
3.0.18-2.ph5
fixed in 3.5.7-1.ph5
0.4%
Theoretical Threat
Not Applicable
CVE-2025-24358NONE0
github.com/gorilla/csrf
v1.7.2
fixed in 1.7.3
0.3%
Theoretical Threat
Not Applicable
CVE-2025-47909NONE0
github.com/gorilla/csrf
v1.7.2
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39882NONE0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp
v1.34.0
fixed in 1.43.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.24.13
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.24.13
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.24.13
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.24.13
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.24.13
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.24.13
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable