VDB
GCVE-110-BRLY-2026-035
GCVE-110-BRLY-2026-035
Advisory Published
BRLY-2026-035 Critical BINARLY REsearch team identified an exposed GitLab CI/CD Job token embedded in a container image hosted on Docker Hub under the `gitlab` namespace. The leaked token is auto-generated by GitLab for workflow execution (`CI_JOB_TOKEN`) and is used to check out the repository code during the image build process. This token is revoked when the workflow run completes; however, because the image is published to Docker Hub before revocation occurs, an attacker can extract the token from the image and use it to perform unauthorized actions.
References
Browse GCVE Records
556 records in the GCVE database · Updated September 9, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.