github-actions

1 article
sort: new top best
clear filter
0 8/10
vulnerability

Researcher discovered a critical DoS vulnerability in GitHub Actions by exploiting git commit hash collisions—abbreviated 7-character shorthashes can be maliciously collided with, causing tarball resolution failures that break all builds using that action. The researcher accidentally triggered a global outage while demonstrating the attack.

GitHub Actions Teddy Katz actions/docker 76ff57a 76ff57a6c3d817840574a98950b0c7bc4e8a13a8 76ff57aa21370794040cd0caafd84d8a7aa0927c
blog.teddykatz.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details