Critical GnuTLS Token Leak Poses Internet-Wide Threat

Critical GnuTLS Token Leak Poses Internet-Wide Threat

First seen 10 Sep 2026, 15:20 UTC Cybernewstrufflesecurity.com 68.2

Article Content

Browse articles
ThreatCluster

A GitLab token with Owner access to GnuTLS and 55 other projects was exposed in a public CI artifact, allowing potential direct code manipulation. Discovered by Truffle Security, the token had api scope, enabling it to push code without approval. GnuTLS is a widely used library for SSL, TLS, and DTLS protocols, integral to many Linux distributions and tools like cURL and Wget. The token was publicly accessible for a day due to a misconfigured CI pipeline in the openconnect/ocserv project. Truffle Security disclosed the leak on June 17, 2026, and the token was revoked shortly thereafter. No malicious activity was detected following the exposure. The incident highlights the risks of mismanaged CI processes in open-source projects.

Key Points: • A GitLab token with Owner access to GnuTLS was exposed, risking major supply chain attacks. • The token was publicly accessible for a day due to CI misconfiguration, allowing potential code pushes. • Truffle Security disclosed the leak and the token has since been revoked with no malicious activity found.

Ask AI about this cluster

Timeline

2026-01-11
Token exposure began
The CI pipeline in the openconnect/ocserv project started exposing the token in public artifacts.
Cybernews
2026-06-17
Leak disclosed
Truffle Security reported the exposed token to the maintainers, who revoked it within hours.
Cybernews
2026-09-10
Public report published
Truffle Security published findings on the token leak, detailing its potential impact on GnuTLS and other projects.
trufflesecurity.com