BleedWatch
00 // INTEL / ADVISORIES

Public BleedWatch Vulnerability Advisories (BVA)

Public advisories summarize externally observable exposure patterns, affected ecosystems, and remediation context. The dashboard remains the source of record for customer-specific live evidence.

Filter
IDTitleSeverityEcosystemPublishedLink
BVA-2026-0142
Docker build layer exposes live AWS deploy role
SaaS
criticalDocker / AWS2026-05-06Open
BVA-2026-0138
GitHub Actions pull_request_target chain with write token
Fintech
highGitHub Actions2026-05-03Open
BVA-2026-0129
NPM package publishes sourcemap with internal API host
Developer tools
mediumNPM2026-04-28Open
BVA-2026-0117
PyPI wheel contains forgotten staging credential
Healthcare
highPyPI2026-04-20Open
BVA-2026-0104
Wildcard CORS on billing subdomain enables token exposure
Commerce
mediumWeb2026-04-11Open
BVA-2026-0098
Public container registry leaks deploy metadata
AI infrastructure
lowDocker2026-04-04Open

ALREADY SHIPPED

Refresh applied. Live data fed from app.bleedwatch.com.

The public shell is reviewable here; customer-specific advisory evidence, ownership, and remediation routing are served from the authenticated dashboard.