VDB
GCVE-110-BRLY-2026-012
GCVE-110-BRLY-2026-012
Advisory Published
BRLY-2026-012 Critical BINARLY REsearch team identified an exposed GitHub Personal Access Token (PAT) embedded in container images hosted on Docker Hub under the Apache namespace. The token does not expire and grants extensive privileges across multiple GitHub organizations and repositories, including administrative access to organizations, private repositories, package registries, and GitHub Actions workflows. An attacker with access to this token could clone or modify private source code, tamper with CI/CD pipelines, manage runners, and potentially plant backdoors in software distributed to downstream users.
References
Browse GCVE Records
556 records in the GCVE database · Updated September 9, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.