WhisperX tag archive

#hardcoded-secret

This page collects WhisperX intelligence signals tagged #hardcoded-secret. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-26 05:54:09 · GitHub Issues

1. Kailash API Gateway Ships Hardcoded JWT Secret in Public Repository, Enabling Token Forgery

A critical security vulnerability has been identified in Kailash's API Gateway middleware component, where a hardcoded default JWT signing key is embedded directly in publicly accessible open-source code. The finding, cataloged as F-C-35 during the Wave 5 portfolio specification audit, exposes a signing key measuring j...