Tag
Pipelines-as-Code (CVE-2026-54167) is vulnerable to GitHub App JWT exfiltration because it incorrectly trusts the 'X-GitHub-Enterprise-Host' header to define the API endpoint before validating incoming webhook signatures.