Official company update
SSRF in Harbor Webhooks: Any User Can Reach the Server’s Cloud Credentials
OX Security·ox.security·
What the source says
OX Research disclosed an SSRF vulnerability in Harbor, the CNCF open-source container registry. Any registered user who can create a project can point a webhook at the cloud metadata endpoint and walk away with the server’s IAM credentials. No admin role, no user interaction, and no need to stay online. Set the webhook, wait for […] The post SSRF in Harbor W
Checking access…
The original publication, including any images and updates, remains with the publisher.
Checking free source access…
More about OX Security
Official · ox.security“Shai-Hulud: Here We Go Again” – “tensorlake” npm Package Hit With MalwareOfficial · ox.securityCVE-2026-93355: Account Takeover in LiteLLMOfficial · ox.securityPhantomSub: Malicious npm Campaign Secretly Adds Users to WhatsApp Spam ChannelsOfficial · ox.securityHow MCP Is Bypassing a Decade of Cloud Security Best Practices