trufflesecurity.com
Critical GnuTLS Token Leak Poses Internet-Wide Threat
Article Content
A GitLab token with Owner access to GnuTLS and 55 other projects was exposed in a public CI artifact, allowing potential direct code manipulation. Discovered by Truffle Security, the token had api scope, enabling it to push code without approval. GnuTLS is a widely used library for SSL, TLS, and DTLS protocols, integral to many Linux distributions and tools like cURL and Wget. The token was publicly accessible for a day due to a misconfigured CI pipeline in the openconnect/ocserv project. Truffle Security disclosed the leak on June 17, 2026, and the token was revoked shortly thereafter. No malicious activity was detected following the exposure. The incident highlights the risks of mismanaged CI processes in open-source projects.
Key Points: • A GitLab token with Owner access to GnuTLS was exposed, risking major supply chain attacks. • The token was publicly accessible for a day due to CI misconfiguration, allowing potential code pushes. • Truffle Security disclosed the leak and the token has since been revoked with no malicious activity found.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.