VDB

GCVE-110-BRLY-2026-012

GCVE-110-BRLY-2026-012
Advisory Published
Vulnetix · Advisory published September 3, 2026
BRLY-2026-012 Critical BINARLY REsearch team identified an exposed GitHub Personal Access Token (PAT) embedded in container images hosted on Docker Hub under the Apache namespace. The token does not expire and grants extensive privileges across multiple GitHub organizations and repositories, including administrative access to organizations, private repositories, package registries, and GitHub Actions workflows. An attacker with access to this token could clone or modify private source code, tamper with CI/CD pipelines, manage runners, and potentially plant backdoors in software distributed to downstream users.

Browse GCVE Records

556 records in the GCVE database · Updated September 9, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›