Source Code Publicity in May 2026
On September 16, CrowdSec was knowledgeable of a supply code leak involving our GitHub repository, which occurred in May 2026. Our staff verified and confirmed the report. CrowdSec supply code consists of two elements: a non-public one and one other that hosts our Free Open Source Software (i.e., the Security Engine), which is public by design and subsequently out of scope. The personal half, although, comprises the supply code for our SaaS console, some AWS Cloud routines, some connectors, and automations.
The information headline claiming 300 totally different repositories is correct (whenever you embody the 130+ public ones), although that quantity largely displays the code’s subdivision reasonably than a selected quantity. We don’t affirm any “different file contained” or “inside improvement materials”, since all of the code is revealed in these repositories. The API associated info is the token utilized by the CI/CD element itself. (see beneath)
No shopper information, login/password, title, group, or anything was leaked, and CrowdSec doesn’t retailer PII or shopper logs; the influence is restricted to CrowdSec. Our staff shortly hunted for any token, credential, or delicate leak that might allow lateral motion however discovered none to date.
The code contained in these personal repositories has worth however can’t actually hurt CrowdSec, since our effectivity depends upon our community impact and dimension, which code alone can’t replicate. We usually audited the SaaS supply code, and its leakage shouldn’t pose an instantaneous risk both. Most of the leaked code has advanced considerably over these 4 months, however we’ll intently monitor for any irregular exercise. Also, utilizing it exterior of CrowdSec appears unlikely as a result of it solely interacts with our information and instruments and can’t actually be leveraged in one other context.
We will preserve you up to date as we proceed investigating, however the Tanstack compromise could be very prone to have been the leak vector (extra about it here), as within the case of the Mistral AI case. This element was utilized in our group in May and seems to have been backdoored to extract an API key with authorization to learn the personal codebase. The leak was solely exploitable throughout a brief timeframe in May 2026.
We however instantly rotated all required tokens & credentials to stop additional incidents.
The staff wish to thank Fuites Infos for his or her well timed, skilled outreach in reporting the problem.


