On 22 September 2026, GitGuardian published research showing that 474 GitHub App private keys found in public leaks still worked, some of them years after they were exposed. The researchers took more than 500,000 leaked RSA private keys from their dataset, narrowed them to 4,802 found next to a GitHub App ID, and tested each one against GitHub's API. About 10% authenticated, as 440 distinct Apps. Many held serious rights: 207 could write repository content, 98 could control workflows and 44 had organisation administration rights. One key, leaked in April 2025, belonged to an App installed in a US Centers for Disease Control and Prevention (CDC) organisation with write access to private repositories; it was revoked on 18 September 2026 after GitGuardian reported it. Another reached about 300 organisations. GitHub App private keys do not expire. No malicious use has been confirmed.
Key takeaways
- GitGuardian found that 474 of 4,802 leaked GitHub App private keys (about 10%) still authenticated, representing 440 distinct Apps.
- A GitHub App private key lets its holder mint fresh short-lived tokens for every installation of that App, so a leaked key works until someone revokes it. As GitGuardian puts it, "GitHub App keys never expire".
- Exposed Apps included one installed in about 300 organisations, one in BuildBuddy's organisation and one with write access to CDC repositories, which GitGuardian said could have allowed code execution in CDC's Azure tenant.
- This is an exposure study. GitGuardian only checked that keys were live; BuildBuddy found no sign of malicious use, and no misuse of the CDC key has been reported.
- The identity lesson: a GitHub App is a machine identity with an owner, permissions and a credential, and it needs the same inventory, rotation and leak monitoring as any other.
At a glance
| Organisations | Owners and installers of 440 GitHub Apps, including the "Access Tokens for GitHub Actions" App (about 300 organisations, among them Civica and Sierra Nevada Corp), BuildBuddy, Crusher.dev and a CDC-linked App |
|---|---|
| When | Keys leaked between 2020 and 2025 according to GitGuardian's examples; research published 22 September 2026 |
| Attacker | None known. Found by GitGuardian researchers testing keys from public leaks |
| Entry point | GitHub App private keys committed or otherwise leaked publicly, 156 of them in repositories the App's owner did not control |
| Identities abused | GitHub App private keys (RSA signing keys) and the installation tokens they can mint |
| Impact | 474 live keys with access ranging from reading code to organisation administration; no confirmed misuse; CDC, BuildBuddy and Access Tokens for GitHub Actions keys revoked or rotated after disclosure |
| Category | NHI. Incident class: exposure, no confirmed misuse (live keys found in public leaks by researchers) |
What happened
GitHub Apps are the recommended way to give automation access to GitHub. Each App has a private key. Whoever holds it can sign a short-lived JSON Web Token, exchange it for an installation token and act with the App's permissions in every organisation that installed it. InfoWorld notes that installation tokens last an hour and the signed tokens only minutes, but the private key itself does not expire and has to be revoked by hand.
GitGuardian's Gaetan Ferry started from more than 500,000 RSA private keys in the company's dataset of publicly leaked secrets, which InfoWorld says it has collected since 2019. He kept the 4,802 that appeared in a GitHub context with an App ID nearby, signed a token with each and called GitHub's /app endpoint, which only returns the App's details if the key is valid. 474 keys worked. About 72% of those Apps had some access to repository content, 207 could write to it, 40 could administer self-hosted runners, 98 could control workflows and 44 had organisation administration rights. Infosecurity Magazine reported GitGuardian's view that such permissions "could allow a complete takeover of an organization or code execution on its internal infrastructure." In 156 cases the key had leaked in a repository the App's maintainer did not own, where the owner was unlikely to notice.
The examples show how long the exposure lasts. A test key for Crusher.dev leaked in November 2020 and still worked at publication, although the project had been unmaintained for about three years. The "Access Tokens for GitHub Actions" key leaked in January 2024 while the App was installed in about 300 organisations; its maintainer rotated it after disclosure. BuildBuddy's internal App key leaked in June 2025; Infosecurity reported that "BuildBuddy took the App down and found no sign of malicious use." The CDC-linked key leaked in April 2025 and gave write access to two private repositories, including one tied to the agency's Azure environment. "The app has write access. It can therefore poison the code stored in them," Ferry said, as quoted by Cybernews. GitGuardian did not touch the repository. It reported the key through the HHS disclosure portal on 4 September 2026, received an acknowledgement on 9 September and saw the key revoked on 18 September after several follow-ups.
Cybernews said it is not known whether an attacker used the CDC key and that no related breach has been confirmed. GitGuardian notified the owners of the affected Apps. Its summary: "A leaked GitHub App private key, left unrotated, is a permanent door."
Timeline
| Date | Event |
|---|---|
| November 2020 | The Crusher-Test App key for Crusher.dev leaks; it still works at publication. |
| January 2024 | The "Access Tokens for GitHub Actions" App key leaks while installed in about 300 organisations. |
| April 2025 | A key for a CDC-linked App with write access to private repositories leaks. |
| June 2025 | BuildBuddy's internal App key leaks. |
| 4 September 2026 | GitGuardian reports the CDC key through the HHS vulnerability disclosure portal. |
| 18 September 2026 | The CDC key is revoked after repeated follow-ups. |
| 22 September 2026 | GitGuardian publishes its research on 474 working GitHub App keys. |
| 23 September 2026 | Infosecurity Magazine, Cybernews and InfoWorld report the findings. |
How it happened: the identity attack path
- A powerful, non-expiring credential. Each GitHub App is authenticated by a private key that does not expire and can mint tokens for every installation.
- The key leaks. Keys were committed to public repositories or other public places, sometimes in projects the App's owner did not control.
- No one notices. The leak is not detected or the key is not rotated, even when the project is abandoned.
- Anyone can authenticate. A finder signs a token with the key and the App ID and is accepted by GitHub, as GitGuardian showed for 474 keys.
- Permissions decide the damage. Depending on the App, the holder could read or write code, change workflows, control self-hosted runners or administer organisations.
Impact
- Confirmed exposure: 474 working keys for 440 GitHub Apps, with 207 able to write repository content and 44 holding organisation administration rights, according to GitGuardian.
- No confirmed misuse: BuildBuddy found no sign of malicious use. Whether anyone used the CDC key is not known, and no related breach has been reported. The CDC and HHS have not commented publicly.
- Potential: code tampering in installed repositories, workflow changes that steal CI secrets, and code execution through self-hosted runners or connected cloud environments such as the CDC's Azure tenant.
- Response: the CDC key was revoked, the Access Tokens for GitHub Actions key was rotated and BuildBuddy took its App down after disclosure. GitGuardian says the Crusher.dev installations still worked at publication.
What this means for NHI governance
GitHub Apps are usually the better choice than personal access tokens, because they issue short-lived tokens with set permissions. This research shows the weak point: the private key behind the App is long-lived, and if it leaks, every safeguard downstream is bypassed. Many of these Apps were small, internal or abandoned, with one installation and no one watching. That is the profile of an orphaned non-human identity, and it is why keys from 2020 still worked in 2026.
The fix is ordinary lifecycle management applied to App keys: know which Apps your organisation owns and has installed, who is responsible for each, where its key is stored, and when it was last rotated. Keys belong in a secrets manager or hardware-backed store, not in repositories, and any key that may have leaked should be rotated rather than assumed safe. See our NHI Ownership Guide and Cryptographic Key Management Guide.
Recommendations
- Revoke and rotate any App key that may have leaked. Generate a new key, delete the old one in the App settings and review the App's recent activity. See the Leaked Credential Response Playbook.
- Inventory GitHub Apps and their owners. List every App your organisation owns and every third-party App installed, with a named owner and a reason to exist. See our NHI Ownership Guide.
- Store App keys like signing keys. Keep them in a secrets manager or key vault, never in repositories or images, and rotate them on a schedule. See our Cryptographic Key Management Guide.
- Cut App permissions to the minimum. Remove organisation administration, workflow and runner permissions that the App does not need, and limit installations to specific repositories.
- Scan for leaked keys continuously. Monitor public sources as well as your own code, since GitGuardian found 156 keys in repositories their owners did not control. See our Secrets Management Guide.
- Retire abandoned Apps. Delete Apps for dead projects and uninstall unused third-party Apps, so a forgotten key has nothing to open.
Frequently asked questions
Do GitHub App private keys expire?
No. The installation tokens a GitHub App uses expire after an hour, but the private key that creates them stays valid until it is deleted in the App's settings. That is why GitGuardian found keys leaked in 2020 that still authenticated in 2026.
Was the CDC breached through a leaked GitHub App key?
No breach has been confirmed. A key for a CDC-linked App with write access to two private repositories was publicly exposed from April 2025 and revoked on 18 September 2026 after GitGuardian reported it. GitGuardian did not access the repositories, and it is not known whether anyone else used the key.
How do I check whether my GitHub App key has leaked?
Search your repositories, container images and package artefacts for private key files, use a secret scanner that covers public sources, and review the App's activity log. If there is any doubt, generate a new key and delete the old one.
Related NHI Mgmt Group resources
Home Depot Token Exposure 2025 · CISA Private-CISA GitHub Leak 2026 · GhostAction Returns 2026 · NHI Ownership Guide · Cryptographic Key Management Guide
How NHI Mgmt Group can help
Integration identities such as GitHub Apps often outlive the projects and people that created them. We help teams inventory them, assign owners, rotate their keys and monitor for leaks before a forgotten credential becomes a way in. See our NHI and AI agent security training.
References
- GitGuardian: GitHub App Private Keys: 474 Leaked Keys Still Work (22 September 2026)
- Infosecurity Magazine: Hundreds of Leaked GitHub App Keys Still Authenticate (23 September 2026)
- Cybernews: Leaked GitHub key exposed CDC-linked code to poisoning risk (23 September 2026)
- InfoWorld: GitHub App keys can still enable takeovers long after they are forgotten (23 September 2026)