CVE-2025-32111

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-credentials: false" for actions/checkout.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-260

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-06: 110-06
Referenced assets1 URL
By indicator
Full discourse1 post
  • Tech At Bloomberg@TechAtBloomberg

    @dns43 @PurdueEngineers @torresariass This isn't theoretical. Software Dark Matter led to 3 zero-days: a leaked GitHub push token baked into the popular https://bloom.bg/4ee6jMc Docker image (CVE-2025-32111) + static, reused SSH host keys in Jenkins' ssh-agent image (CVE-2025-32754/-32755) #SupplyChainSecurity (3/5) https://t.co/kU8G6D4Trz

    1000026
    19.1K followersView on X

Explore more