Vulnerability Reportgoharbor/harbor-core:v2.14.4

goharbor/harbor-core:v2.14.4goharbor/harbor-core:v2.14.4-rc1
DIGESTsha256:8d3e4309e45488a013c2e3ad7c60c17581bba3ff718b545e2b40c7363f1a62c9

Executive Summary

Threat Score
25/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The two most notable vulnerabilities are CVE-2026-41889 and CVE-2026-45447, both requiring specific configurations or code paths to be exploitable. The remaining 30 exposed vulnerabilities are lower severity, and all post-exploit findings are low severity. Overall, the risk is moderate, but patching these two CVEs is advisable to reduce the attack surface.

Vulnerabilities

Vulnerability Log

81 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-41889MEDIUM6.66
github.com/jackc/pgx/v4
v4.18.3
No fix yet
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-45447MEDIUM6.48
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
1.4%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-41888MEDIUM5.52
github.com/distribution/distribution
v2.8.2+incompatible
No fix yet
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-34181MEDIUM5.35
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34183MEDIUM5.1
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-35172MEDIUM5.1
github.com/distribution/distribution
v2.8.2+incompatible
No fix yet
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39820MEDIUM5.1
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-7383MEDIUM4.67
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.2.13-5.ph5
fixed in 1.3.2-1.ph5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc
2.36-23.1.ph5
fixed in 2.43-3.ph5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc
2.36-23.1.ph5
fixed in 2.43-3.ph5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-libs
2.36-23.1.ph5
fixed in 2.43-3.ph5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-libs
2.36-23.1.ph5
fixed in 2.43-3.ph5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-45186LOW3.83
expat-libs
2.7.5-1.ph5
fixed in 2.8.1-1.ph5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39826LOW3.67
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-6429LOW3.31
curl
8.19.0-1.ph5
fixed in 8.19.0-2.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
curl-libs
8.19.0-1.ph5
fixed in 8.19.0-2.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW3.31
curl-libs
8.19.0-1.ph5
fixed in 8.19.0-2.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34181LOW3.21
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42768LOW3.21
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-41080LOW3.15
expat-libs
2.7.5-1.ph5
fixed in 2.8.0-1.ph5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33811LOW3.06
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Post-ExploitContext importance: MEDIUM
CVE-2026-42764LOW3.01
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW3.01
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW3.01
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW3.01
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42764LOW3.01
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-45447LOW2.92
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-7383LOW2.8
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7598LOW2.78
libssh2
1.11.0-4.ph5
fixed in 1.11.1-3.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-32952LOW2.7
github.com/Azure/go-ntlmssp
v0.0.0-20221128193559-754e69321358
fixed in 0.1.1
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-4873LOW2.7
curl
8.19.0-1.ph5
fixed in 8.19.0-2.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
curl
8.19.0-1.ph5
fixed in 8.19.0-2.ph5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-7009LOW2.7
curl
8.19.0-1.ph5
fixed in 8.20.0-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
curl
8.19.0-1.ph5
fixed in 8.20.0-1.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4873LOW2.7
curl-libs
8.19.0-1.ph5
fixed in 8.19.0-2.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
curl-libs
8.19.0-1.ph5
fixed in 8.19.0-2.ph5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-7009LOW2.7
curl-libs
8.19.0-1.ph5
fixed in 8.20.0-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
curl-libs
8.19.0-1.ph5
fixed in 8.20.0-1.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW2.7
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-33540LOW2.63
github.com/distribution/distribution
v2.8.2+incompatible
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34180LOW2.55
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW2.29
curl
8.19.0-1.ph5
fixed in 8.19.0-2.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW2.29
curl
8.19.0-1.ph5
fixed in 8.19.0-2.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW2.29
curl-libs
8.19.0-1.ph5
fixed in 8.19.0-2.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW2.29
curl-libs
8.19.0-1.ph5
fixed in 8.19.0-2.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.29
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-32286LOW2.29
github.com/jackc/pgproto3/v2
v2.3.3
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-33814LOW2.29
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-39836LOW2.29
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW2.26
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW2.26
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-35206LOW2.24
helm.sh/helm/v3
v3.18.5
fixed in 3.20.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW1.99
curl
8.19.0-1.ph5
fixed in 8.19.0-2.ph5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW1.89
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW1.81
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW1.81
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW1.81
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW1.62
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-69720NONE0
ncurses-libs
6.5-1.ph5
fixed in 6.5-2.ph5
0.4%
Theoretical Threat
Not Applicable
BDSA-2026-9096NONE0
curl
8.19.0-1.ph5
fixed in 8.20.0-1.ph5
Not Applicable
BDSA-2026-9096NONE0
curl-libs
8.19.0-1.ph5
fixed in 8.20.0-1.ph5
Not Applicable
BDSA-2026-9020NONE0
libssh2
1.11.0-4.ph5
fixed in 1.11.1-3.ph5
Not Applicable
CVE-2026-42765NONE0
openssl
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42765NONE0
openssl-libs
3.0.18-3.ph5
fixed in 3.5.7-1.ph5
0.4%
Theoretical Threat
Not Applicable
CVE-2025-24358NONE0
github.com/gorilla/csrf
v1.7.2
fixed in 1.7.3
0.3%
Theoretical Threat
Not Applicable
CVE-2025-47909NONE0
github.com/gorilla/csrf
v1.7.2
No fix yet
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39882NONE0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp
v1.34.0
fixed in 1.43.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.25.9
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.25.9
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.25.9
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable