Vulnerability Reportgoharbor/harbor-core:v2.15.2

goharbor/harbor-core:v2.15.2goharbor/harbor-core:v2.15.2-rc3
digestsha256:d7b780d23721a000f0fb8e181add6675eafa336de5d033b77fd7da0c171ff7f7

Executive Summary

Last scanned:

Threat Score
0/100NEEDS ATTENTION
Reputation
RELIABLE

AI verdict failed due to an error.

Vulnerabilities

Vulnerability Log

16 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-55200NONE0
libssh2
1.11.1-3.ph5
fixed in 1.11.1-4.ph5
2.0%
Low-Moderate Risk
Not Applicable
CVE-2026-39822NONE0
stdlib
v1.26.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Not Applicable
CVE-2026-55199NONE0
libssh2
1.11.1-3.ph5
fixed in 1.11.1-5.ph5
0.9%
Theoretical Threat
Not Applicable
CVE-2026-32952NONE0
github.com/Azure/go-ntlmssp
v0.1.0
fixed in 0.1.1
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-35172NONE0
github.com/distribution/distribution
v2.8.2+incompatible
No fix yet
0.5%
Theoretical Threat
Not Applicable
CVE-2026-41888NONE0
github.com/distribution/distribution
v2.8.2+incompatible
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42505NONE0
stdlib
v1.26.4
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-11850NONE0
krb5
1.20.2-13.ph5
fixed in 1.20.2-14.ph5
0.3%
Theoretical Threat
Not Applicable
CVE-2026-35206NONE0
helm.sh/helm/v3
v3.18.5
fixed in 3.20.2
0.2%
Theoretical Threat
Not Applicable
CVE-2026-33540NONE0
github.com/distribution/distribution
v2.8.2+incompatible
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2025-24358NONE0
github.com/gorilla/csrf
v1.7.2
fixed in 1.7.3
0.4%
Theoretical Threat
Not Applicable
CVE-2025-47909NONE0
github.com/gorilla/csrf
v1.7.2
No fix yet
0.2%
Theoretical Threat
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.52.0
No fix yet
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.55.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.37.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.81.1
fixed in 1.82.1
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.