Exposure DB
1,048 exposure sites - every place a customer-controlled credential or secret can leak - each mapped to the edge it emits, its collection recipe, and what leaks.
406
aws
377
azure
265
gcp
563
critical severity
250
medium severity
233
high severity
2
low severity
bigquery.datasets.get.{description,labels.<value>} - leaks credential, api_key, sensitive_data, pii
bigquery.jobs.get.configuration.query.{query,queryParameters[]} - leaks credential, customer_data, pii, sensitive_data
bigquery.jobs.getQueryResults.rows[].f[].v - leaks credential, customer_data, pii, sensitive_data
bigquery.routines.get.definitionBody - leaks source_code_secret, credential, password, api_key, private_key, sensitive_data
bigquery.rowAccessPolicies.get.filterPredicate - leaks credential, api_key, sensitive_data, pii
bigquery.tables.get.{description,labels.<value>} - leaks credential, api_key, sensitive_data, pii
bigquery.tabledata.list.rows[].f[].v - leaks credential, customer_data, pii, sensitive_data
bigtableadmin.projects.instances.get.labels.<value> - leaks credential, api_key, sensitive_data, pii
google.bigtable.v2.Bigtable.ReadRows.ReadRowsResponse.chunks[].value - leaks credential, customer_data, pii, sensitive_data
bigtableadmin.projects.instances.tables.get.columnFamilies.<value>.gcRule - leaks sensitive_data
privateca.projects.locations.caPools.certificates.get.{pemCertificate,pemCertificateChain[]} - leaks certificate, sensitive_data
certificatemanager.projects.locations.certificates.get.labels.<value> - leaks credential, api_key, sensitive_data, pii
certificatemanager.projects.locations.certificates.get.pemCertificate - leaks certificate, sensitive_data
certificatemanager.projects.locations.dnsAuthorizations.get.dnsResourceRecord.{name,type,data} - leaks credential, sensitive_data
certificatemanager.projects.locations.certificates.create/certificatemanager.projects.locations.certificates.patch.request.selfManaged.pemPrivateKey - leaks private_key, credential
compute.securityPolicies.get.rules[].description - leaks credential, api_key, sensitive_data, pii
compute.securityPolicies.get.rules[].match.expr.expression - leaks credential, api_key, sensitive_data, pii
compute.securityPolicies.get.rules[].headerAction.requestHeadersToAdds[].headerValue - leaks credential, api_key, oauth_token, sensitive_data
cloudasset.exportAssets.outputConfig.gcsDestination.uri -> exported asset JSON - leaks credential, pii, customer_data, sensitive_data
cloudasset.feeds.get.{assetNames[],condition.{expression,title,description},feedOutputConfig} - leaks credential, api_key, sensitive_data, pii
cloudasset.analyzeIamPolicy.mainAnalysis.analysisResults[].{iamBinding,accessControlLists,identityList} - leaks pii, sensitive_data
cloudasset.searchAllResources.results[].{displayName,description,labels.<value>,additionalAttributes} - leaks credential, pii, sensitive_data
cloudbuild.projects.locations.bitbucketServerConfigs.get.apiKey - leaks api_key, webhook_secret, credential
cloudbuild.projects.builds.get.logUrl/logsBucket -> Cloud Logging or Cloud Storage log entries - leaks credential, password, api_key, oauth_token, private_key, connection_string, sensitive_data
cloudbuild.projects.builds.get.steps[].args[] - leaks credential, password, api_key, access_key, secret_key, oauth_token, sensitive_data
cloudbuild.projects.builds.get.steps[].env[] - leaks credential, password, api_key, access_key, secret_key, oauth_token, connection_string
cloudbuild.projects.builds.get.substitutions.<value> - leaks credential, password, api_key, access_key, secret_key, oauth_token, sensitive_data
cloudbuild.projects.triggers.get.build.{steps[],substitutions,options.env[]} - leaks source_code_secret, credential, password, api_key, private_key
clouddeploy.projects.locations.customTargetTypes.get.customActions.{renderAction,deployAction} - leaks source_code_secret, credential, password, api_key, private_key
clouddeploy.projects.locations.customTargetTypes.get.tasks.{render,deploy}.container.{env.<value>,command[],args[]} - leaks credential, password, api_key, access_key, secret_key, oauth_token, connection_string, sensitive_data
clouddeploy.projects.locations.deliveryPipelines.get.{annotations.<value>,labels.<value>,description} - leaks credential, api_key, sensitive_data, pii
clouddeploy.projects.locations.deliveryPipelines.releases.get.{annotations.<value>,labels.<value>,description} - leaks credential, api_key, sensitive_data, pii
clouddeploy.projects.locations.deliveryPipelines.releases.get.buildArtifacts[].{image,skaffoldConfigUri,manifestPath} - leaks source_code_secret, credential, password, api_key, private_key
clouddeploy.projects.locations.targets.get.{annotations.<value>,labels.<value>,description} - leaks credential, api_key, sensitive_data, pii
dns.managedZones.get.{description,labels.<value>} - leaks credential, api_key, sensitive_data, pii
dns.resourceRecordSets.list.rrsets[].rrdatas[] - leaks credential, api_key, sensitive_data, pii
cloudidentity.groups.get.{groupKey.id,additionalGroupKeys[].id,displayName,description} - leaks pii, sensitive_data
cloudidentity.inboundOidcSsoProfiles.create/cloudidentity.inboundOidcSsoProfiles.patch.request.rpConfig.clientSecret - leaks oauth_token, secret_key, credential
cloudidentity.groups.memberships.get.{preferredMemberKey.id,roles[].name} - leaks pii, sensitive_data
run.projects.locations.services.get.buildConfig.environmentVariables.<value> - leaks credential, password, api_key, access_key, secret_key, oauth_token, connection_string
run.projects.locations.jobs.get.template.template.containers[].{command[],args[]} - leaks credential, password, api_key, access_key, secret_key, oauth_token, sensitive_data
run.projects.locations.jobs.get.template.template.containers[].env[].value - leaks credential, password, api_key, access_key, secret_key, oauth_token, connection_string
run.projects.locations.services.get.template.containers[].{command[],args[]} - leaks credential, password, api_key, access_key, secret_key, oauth_token, sensitive_data
run.projects.locations.services.get.{labels.<value>,annotations.<value>} - leaks credential, api_key, sensitive_data, pii
run.projects.locations.services.get.template.containers[].env[].value - leaks credential, password, api_key, access_key, secret_key, oauth_token, connection_string
run.projects.locations.workerPools.get.template.containers[].{command[],args[]} - leaks credential, password, api_key, access_key, secret_key, oauth_token, sensitive_data
run.projects.locations.workerPools.get.template.containers[].env[].value - leaks credential, password, api_key, access_key, secret_key, oauth_token, connection_string
cloudscheduler.projects.locations.jobs.get.appEngineHttpTarget.{relativeUri,headers.<value>,body} - leaks credential, api_key, oauth_token, customer_data, sensitive_data
cloudscheduler.projects.locations.jobs.get.httpTarget.{uri,headers.<value>,body} - leaks credential, api_key, oauth_token, customer_data, sensitive_data
cloudscheduler.projects.locations.jobs.get.description - leaks credential, api_key, sensitive_data, pii