CVE-2026-55870: GoCD is vulnerable to credential exposure when admins insecurely configure material URLs

Published Sep 21, 2026
·
Updated

GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo portion of source control material URLs through several read-only APIs available to regular authenticated users. Although GoCD recommends dedicated username and password fields or secret-management plugins, legacy configuration permits credentials in material URLs, and not every mixed-use API consistently applies URL masking for every material type. An authenticated user with access to an affected pipeline can obtain credentials embedded in its material URL, while dedicated password fields remain encrypted and are not exposed by this issue. This issue is fixed in version 26.1.0.

Affected Software

1 affected component
GoCD GoCD<26.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GoCD to a version that resolves this vulnerability.

    Fixed in 26.1.0

Event History

Sep 21, 2026
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness

Frequently Asked Questions

1

Which GoCD configurations are exposed?

Affected configurations are source control materials with credentials stored in the URL userinfo portion. Dedicated username and password fields and secret-management plugins are the recommended alternatives; dedicated password fields are not exposed by this issue.

2

What access does an attacker need?

An attacker must be an authenticated regular user with access to an affected pipeline. The credentials can be obtained through several read-only APIs.

3

Are default credential-storage methods affected?

Credentials stored in GoCD's dedicated password fields remain encrypted and are not exposed by this issue. The exposure applies to legacy configurations that embed credentials directly in material URLs.

4

What can be done before upgrading?

Remove credentials from source control material URLs and use dedicated username and password fields or a secret-management plugin instead. Upgrade to GoCD 26.1.0 to apply the fix.

5

How can teams identify potentially affected pipelines?

Review source control material URLs for embedded userinfo credentials. Pipelines using those legacy URL-embedded credentials should be treated as exposed if accessible to authenticated users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203