CVE-2019-19025: Linuxfoundation Harbor

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.

Affected products

  • Linuxfoundation Harbor: from 1.7.0, before 1.8.6 (fixed in 1.8.6); from 1.9.0, before 1.9.3 (fixed in 1.9.3)
  • Pivotal VMware Harbor Registry: affected versions not specified

Published 2020-03-20. Last modified 2026-06-17.