OX Security researchers have disclosed a server-side request forgery (SSRF) vulnerability in Harbor, the CNCF open-source container registry. The flaw can allow a registered user with permission to create a project to configure a webhook that reaches internal services, including cloud metadata endpoints.

Because Harbor webhooks automatically send requests when events such as image pushes occur, an attacker can potentially make Harbor perform the request on their behalf. If the underlying server has access to cloud instance metadata, this could expose IAM credentials and other sensitive cloud information.

Harbor's security advisories and subsequent releases identify the webhook SSRF issue and related fixes, emphasizing the need for affected deployments to update to a patched version.