Information Disclosure in GoCD Continuous Delivery Server
CVE-2026-55870
2.3LOW
What is CVE-2026-55870?
Prior to version 26.1.0, GoCD, a continuous delivery server developed by ThoughtWorks, was vulnerable to an information disclosure issue. This vulnerability allowed authenticated users to obtain unmasked credentials stored in the userinfo portion of source control material URLs via several read-only APIs. Although GoCD recommends the use of dedicated username and password fields or secret-management plugins, legacy configurations permitted credentials in URLs, which were not consistently protected. This flaw highlighted the importance of adhering to security best practices in credential management. The issue has since been addressed in version 26.1.0.
Affected Version(s)
gocd < 26.1.0
