VDB
GCVE-110-BRLY-2026-011
GCVE-110-BRLY-2026-011
Advisory Published
BRLY-2026-011 Critical BINARLY REsearch team identified an exposed GitHub Personal Access Token (PAT) embedded in multiple container images hosted on Docker Hub under the Apache namespace. The token does not expire and grants repository and user-level privileges for both public and private GitHub repositories, including private Apache Software Foundation infrastructure repositories. An attacker with access to this token could clone or modify private source code, abuse CI/CD pipelines that rely on these repositories, and potentially use the compromised account as a foothold into the Apache organization.
References
Browse GCVE Records
556 records in the GCVE database · Updated September 9, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.