GitHub Bug Leaked Webhook Secrets to Recipient Endpoints for Months
Hacker News·high signal
GitHub disclosed that between September 2025 and January 2026, webhook secrets were inadvertently included in an HTTP header on webhook deliveries, potentially exposing them to recipient endpoints. The vulnerability (GH-[redacted]-a1) is generating significant developer concern, with 30+ points and active discussion on Hacker News urging affected users to rotate secrets immediately. CircleCI and other OAuth-integrated services have issued follow-up advisories for projects that may be impacted.