HACKERONE

curl: Hash exposed in public repository_H1:3419617

Description

An image hash is publicly exposed on Github

Steps to reproduce:
See at >> https://github.com/curl/curl/blob/master/Dockerfile

Solution:
# If you want to keep the hash, the repository should be private
#Use official tags without specific hashes or environment variables

Best,
@skymander

## Impact

An attacker can use this hash to:
* View known vulnerabilities
* View your deployment environment

2. Complete URLs

* Expose your internal infrastructure
* Private repositories
* Specific endpoints
Visit Original Source

Basic Information

ID H1:3419617
Published Nov 11, 2025 at 15:55
Modified Nov 11, 2025 at 16:15

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.