VDB

GCVE-110-BRLY-2026-011

GCVE-110-BRLY-2026-011
Advisory Published
Vulnetix · Advisory published September 3, 2026
BRLY-2026-011 Critical BINARLY REsearch team identified an exposed GitHub Personal Access Token (PAT) embedded in multiple container images hosted on Docker Hub under the Apache namespace. The token does not expire and grants repository and user-level privileges for both public and private GitHub repositories, including private Apache Software Foundation infrastructure repositories. An attacker with access to this token could clone or modify private source code, abuse CI/CD pipelines that rely on these repositories, and potentially use the compromised account as a foothold into the Apache organization.

Browse GCVE Records

556 records in the GCVE database · Updated September 9, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›