frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

GitHub gave webhook secrets away in webhook call

7•time4tea•10h ago
Couldn't see this on a Web page...

From an email:

We're writing to let you know that between September 2025 and January 2026, webhook secrets for webhooks you are responsible for were inadvertently included in an HTTP header on webhook deliveries. This means that any system receiving webhook payloads during this window could have logged the webhook secret from the request headers. Webhook deliveries are encrypted in transit via TLS, so the header containing the secret was only accessible to the receiving endpoint in a base64-encoded format. We have no evidence to suggest your secrets were intercepted. This issue was fixed on January 26, 2026. Please read on for more information.

User privacy and security are essential for maintaining trust, and we want to remain as transparent as possible about events like these. GitHub itself did not experience a compromise or data breach as a result of this event.

* What happened? *

On January 26, 2026, GitHub identified a bug in a new version of the webhook delivery platform where webhook secrets were included in an X-Github-Encoded-Secret HTTP header sent with webhook payloads. This header was not intended to be part of the delivery and made the webhook secret available to the receiving endpoint in a base64-encoded format. Webhook secrets are used to verify that deliveries are genuinely from GitHub, and should only be known to GitHub and the webhook owner.

The bug was limited to only a subset of webhook deliveries that were feature flagged to use this new version of the webhooks platform. The bug was present between September 11, 2025, and December 10, 2025, and briefly on January 5, 2026. The bug was fixed on January 26, 2026

Tell HN: Fiverr left customer files public and searchable

544•morpheuskafka•11h ago•110 comments

Tell HN: Anthropic no longer allows you to fix to specific model version

3•baobabKoodaa•19m ago•0 comments

Ask HN: Can anyone suggest me a SaaS product idea?

2•wasimsk•1h ago•3 comments

Ask HN: Easiest UX for Seniors

49•khoury•3d ago•54 comments

What do you want out of a coding monospace font?

2•d0able•5h ago•4 comments

Ask HN: What Are You Working On? (April 2026)

336•david927•2d ago•1137 comments

Tell HN: Docker pull fails in Spain due to football Cloudflare block

1132•littlecranky67•2d ago•417 comments

GitHub gave webhook secrets away in webhook call

7•time4tea•10h ago•0 comments

Ask HN: Are Web Agencies Cooked?

8•mijustin•11h ago•6 comments

Ask HN: Who needs contributors? (April 2026)

18•Kathan2651•16h ago•7 comments

Ask HN: I quit my job over weaponized robots to start my own venture

110•barratia•19h ago•72 comments

Ask HN: What's your favorite security cam system?

4•SunshineTheCat•13h ago•4 comments

Ask HN: What standards or protocols exist for AI Agent permissions

2•lyfeninja•13h ago•1 comments

Tell HN: GitHub might have been leaking your webhook secrets. Check your emails.

24•ssiddharth•14h ago•6 comments

PersMEM: Persistent Semantic Memory and Multi-Instance Communication for AI

3•asixicle•14h ago•0 comments

Tell HN: OpenAI silently removed Study Mode from ChatGPT

182•smokel•2d ago•77 comments

Claude Code OAuth down for >12 hours

7•pixel_popping•22h ago•7 comments

Technical SEO vs. content optimization: which one moves rankings?

4•zensorsolutions•23h ago•2 comments

Ask HN: LeetCode, anyone still doing it?

8•kwar13•1d ago•9 comments

Ask HN: What are you building that's not AI related?

152•meander_water•5d ago•221 comments

Ask HN: Are you negatively affected by the recent economic stagnation?

6•adinhitlore•1d ago•14 comments

Ask HN: Hiring in the age of AI-assisted coding: what works?

28•nitramm•4d ago•19 comments

Why most AI projects feel useless

7•vaishcodescape•1d ago•6 comments

Ask HN: What should I do with my app? 130 downloads 3 real subscribers

6•oyaa52•3d ago•15 comments

Ask HN: What makes it so hard to keep LLMs online?

3•realberkeaslan•1d ago•8 comments

Tell HN: Another Monday, Another Claude Outage

6•ericol•1d ago•1 comments

Ask HN: What's the best AI model for system design nowadays?

5•jcremona•1d ago•10 comments

Ask HN: Do you trust AI agents with API keys / private keys?

17•devendra116•2d ago•30 comments

How do you validate your GTM Efforts?

3•pranaywankhede•1d ago•4 comments

Ask HN: Anyone using Nostr as a lightweight back end/DB for rapid prototyping?

6•wasimsk•3d ago•2 comments