logo

No keys attached: Exploring GitHub-to-AWS keyless authentication flaws

ID: 50394d48-4c7a-5267-a7ed-876de1c27b75

STIX ID: report--50394d48-4c7a-5267-a7ed-876de1c27b75

Feed Name: Datadog Security Labs

Threat Score
70/100

Date Published: 2023-07-27

Date Updated: 2026-04-27

...
...

Datadog Security Labs details an attack surface in GitHub Actions-to-AWS OIDC setups where IAM trust policies omit or overwrite the JWT subject condition, enabling any GitHub Action to assume vulnerable roles. Using OSINT and automated GitHub Actions token requests, researchers identified hundreds of exposed role ARNs and demonstrated an instance in a UK Government Digital Service account that allowed access to private mirrored repositories; the issue was responsibly disclosed and remediated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.