{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-54167/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Pipelines-as-Code"],"_cs_severities":["high"],"_cs_tags":["cve-2026-54167","credential-theft","red-hat","webserver"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003ePipelines-as-Code versions prior to 0.48.0 contain a critical vulnerability in the handling of GitHub App authentication during webhook processing. The service improperly trusts the 'X-GitHub-Enterprise-Host' HTTP header to determine the GitHub Enterprise API host for token generation requests. An attacker can supply a malicious, attacker-controlled URL in this header within a crafted webhook payload. Because the controller attempts to generate a GitHub App JWT and request an installation access token before validating the webhook signature or confirming that the Enterprise host corresponds to the target repository, the internal GitHub App JWT is transmitted to the attacker-controlled server. This exposure allows attackers to potentially mint GitHub App installation access tokens, assuming they operate within the window of the JWT's validity and the specific App's permissions. This vulnerability affects installations of OpenShift Pipelines-as-Code across multiple version branches.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target instance of Pipelines-as-Code exposed to the internet.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious GitHub webhook payload containing a valid 'installation.id' associated with the target GitHub App.\u003c/li\u003e\n\u003cli\u003eAttacker includes the 'X-GitHub-Enterprise-Host' header in the HTTP request, pointing to an attacker-controlled listener.\u003c/li\u003e\n\u003cli\u003eThe Pipelines-as-Code webhook endpoint receives the payload.\u003c/li\u003e\n\u003cli\u003eThe service initiates token generation by reading the malicious 'X-GitHub-Enterprise-Host' header.\u003c/li\u003e\n\u003cli\u003eThe service signs a GitHub App JWT and transmits it to the attacker-supplied host before verifying the webhook signature.\u003c/li\u003e\n\u003cli\u003eAttacker captures the GitHub App JWT from the outbound request.\u003c/li\u003e\n\u003cli\u003eAttacker uses the captured JWT to impersonate the GitHub App and mint installation access tokens.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to the exfiltration of sensitive GitHub App JWTs, granting the attacker the ability to obtain installation access tokens. This enables unauthorized actors to perform actions within the repository context equivalent to the GitHub App's granted permissions, potentially including code modification, secret exfiltration, or workflow manipulation. The vulnerability impacts all Pipelines-as-Code users utilizing the GitHub App provider model across various versions, specifically those prior to the v0.48.0 security patch.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to Pipelines-as-Code v0.48.0 or later immediately to include the fix for CVE-2026-54167.\u003c/li\u003e\n\u003cli\u003eFor ingress/proxy points in front of the webhook endpoint, implement a rule to strip or validate the 'X-GitHub-Enterprise-Host' header; reject requests that contain this header for GitHub.com installations, and strictly allow only known-good hostnames for GitHub Enterprise Server environments.\u003c/li\u003e\n\u003cli\u003eIf exploitation is suspected, rotate the GitHub App private key immediately and perform an audit of GitHub App installation token usage logs to identify anomalous activity.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the webhook endpoint to only trusted IP ranges associated with authorized Git provider sources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-20T19:14:05Z","date_published":"2026-08-20T19:14:05Z","id":"https://feed.craftedsignal.io/briefs/2026-08-pipelines-as-code-credential-exfiltration/","summary":"Pipelines-as-Code (CVE-2026-54167) is vulnerable to GitHub App JWT exfiltration because it incorrectly trusts the 'X-GitHub-Enterprise-Host' header to define the API endpoint before validating incoming webhook signatures.","title":"Pipelines-as-Code GitHub App Credential Exfiltration via Header Injection","url":"https://feed.craftedsignal.io/briefs/2026-08-pipelines-as-code-credential-exfiltration/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-54167","version":"https://jsonfeed.org/version/1.1"}