Five-Year-Old Bugs in a JSON Parser Open a Code Execution Hole in Self-Managed GitLab
Researchers chained two long-dormant memory-safety bugs in Ruby's Oj JSON parser to achieve remote code execution on self-managed GitLab instances, using nothing more than an ordinary commit and...
GitLab Patches High-Severity Duo AI Identity Flaw and Multiple Authorization, DoS Vulnerabilities
GitLab has released emergency security patches (versions 19.0.1, 18.11.4, 18.10.7) fixing a CVSS 8.2 Duo AI identity flaw (CVE-2026-4868) that could enable lateral movement, alongside a Wiki denial-of-service...
GitLab Releases Critical Security Patch for Multiple High-Severity Vulnerabilities
Security researchers have uncovered vulnerabilities in GitLab’s Community Edition and Enterprise Edition platforms, prompting the company to release critical security patches. On December 10th, 2025, Gitlab released update...
Analysis of recent high-severity vulnerabilities in GitLab and Atlassian products
Both GitLab and Atlassian have recently released critical security patches addressing a series of high-severity vulnerabilities across their core product lines. This coordinated disclosure and remediation effort underscores...
Fog’s dubious GitLab claims: investigation on instances
One name that has been gaining traction since late January is Fog, a ransomware operation that has been particularly vocal about targeting GitLab instances. Fog has claimed responsibility...
Urgent: GitLab warns of critical vulnerability, advises immediate patching
GitLab, a popular DevOps platform, has recently released a critical security update to address several high-severity vulnerabilities. Organizations using GitLab must prioritize upgrading to the latest patched versions...