Information Disclosure in GoCD Continuous Delivery Server
CVE-2026-55870

2.3LOW

Key Information:

Vendor

Gocd

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-55870?

Prior to version 26.1.0, GoCD, a continuous delivery server developed by ThoughtWorks, was vulnerable to an information disclosure issue. This vulnerability allowed authenticated users to obtain unmasked credentials stored in the userinfo portion of source control material URLs via several read-only APIs. Although GoCD recommends the use of dedicated username and password fields or secret-management plugins, legacy configurations permitted credentials in URLs, which were not consistently protected. This flaw highlighted the importance of adhering to security best practices in credential management. The issue has since been addressed in version 26.1.0.

Affected Version(s)

gocd < 26.1.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.