VDB
CVE-2025-30086
CVE-2025-30086
PUBLISHED
CVSS 6.900000095367432 MEDIUM
Possible ORM Leak Vulnerability in the Harbor
EPSS 0.39% · 60.1th percentile
Risk Scores
CVSS v4.0
6.900000095367432
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.39%
60.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | goharbor/harbor | 2.13.0, 0, 2.13.0 |
| n/a | n/a | n/a |
Timeline
- Jul 23, 2025 CVE Published
- Jul 25, 2025 CVE Updated
- Jul 25, 2025 Coalition ESS Score
- Jul 26, 2025 EPSS Score
- Aug 4, 2025 EPSS Score
- Aug 13, 2025 EPSS Score
- Aug 22, 2025 EPSS Score
- Aug 22, 2025 Coalition ESS Score
- Aug 26, 2025 Coalition ESS Score
- Aug 30, 2025 EPSS Score
- Sep 8, 2025 EPSS Score
- Sep 17, 2025 EPSS Score
References
- https://github.com/goharbor/harbor/releases url
- https://www.elttam.com/blog/plormbing-your-django-orm/ url
- https://goharbor.io/blog/ url
- https://github.com/goharbor/harbor/security/advisories/GHSA-h27m-3qw8-3pw8 url
- https://nvd.nist.gov/vuln/detail/CVE-2025-30086 advisory
- https://github.com/goharbor/harbor/commit/dce7d9f5cffbd0d0c5d27e7a2f816f65a930702c url
- https://github.com/goharbor/harbor package
- https://goharbor.io/blog url
- https://www.elttam.com/blog/plormbing-your-django-orm url