Apr 2026
(5 advisories)BVA-2026-0142AWS access key found in prod-tagged Docker imageCriticalDockerBVA-2026-0141Typosquat targeting @bleedwatch/scanner-cliHighNPMBVA-2026-0138Dependency confusion vector in @internal-packageHighNPMBVA-2026-0135Workflow injection via PR title in unsafe checkoutHighGitHubBVA-2026-0130Source map leak exposes API endpointsMediumWeb build
Mar 2026
(5 advisories)BVA-2026-0127Cloudfront origin left reachable through stale DNSMediumDNSBVA-2026-0124Expired OAuth callback host reused by preview appHighGitHubBVA-2026-0119Forged package README links to credential harvesterHighPyPIBVA-2026-0116Image label reveals private registry namespaceMediumDockerBVA-2026-0110Browser bundle includes staging GraphQL tokenCriticalWeb build
Feb 2026
(5 advisories)BVA-2026-0108Abandoned maintainer account publishes postinstall loaderCriticalNPMBVA-2026-0102Container layer retains Terraform backend credentialsCriticalDockerBVA-2026-0097Dark web listing matches production SSO invite tokenHighDark webBVA-2026-0093Unsafe Actions checkout exposes write-scoped tokenHighGitHubBVA-2026-0089Package provenance signature missing after owner transferMediumPyPI
Jan 2026
(5 advisories)BVA-2026-0084Analytics endpoint discloses tenant identifiersMediumWeb buildBVA-2026-0079Build artifact includes `.npmrc` registry tokenCriticalNPMBVA-2026-0075GitHub environment secret exposed by verbose deploy stepHighGitHubBVA-2026-0068DNS takeover risk on retired customer-success subdomainHighDNSBVA-2026-0061Credential dump contains active vendor API passwordCriticalDark web
Dec 2025
(5 advisories)BVA-2025-0157NPM namespace squatter mirrors internal design-system nameHighNPMBVA-2025-0151PyPI wheel executes telemetry beacon during installHighPyPIBVA-2025-0144Docker image exposes CircleCI project slug and token hintMediumDockerBVA-2025-0139Archive artifact preserves `.env.production` fileCriticalGitHubBVA-2025-0134MX record drift points mail flow at abandoned tenantMediumDNS
Nov 2025
(5 advisories)BVA-2025-0128S3-compatible endpoint revealed in frontend source mapMediumWeb buildBVA-2025-0122Kubernetes image tag reuses vulnerable OpenSSL base layerMediumDockerBVA-2025-0117Lookalike PyPI package steals cloud metadata tokenCriticalPyPIBVA-2025-0110GitHub release attachment contains private package lockfileLowGitHubBVA-2025-0106Credential broker domain expires while callback remains trustedHighDNS
Oct 2025
(5 advisories)BVA-2025-0099Open package mirror serves stale vulnerable CLI binaryMediumNPMBVA-2025-0094Public Docker namespace mimics internal billing workerHighDockerBVA-2025-0087Redacted paste still exposes hashed customer emailsMediumDark webBVA-2025-0081Workflow cache leaks private Maven repository URLLowGitHubBVA-2025-0074Package install hook downloads unsigned binary payloadCriticalPyPI
SUBSCRIBE
Subscribe to new advisories.
Receive public BVA records by email or feed as soon as redaction and publication review are complete.
Live records sync from app.bleedwatch.com on a continuous schedule. Static IDs preserved.
Open advisories