< ciso
brief />
Tag Banner

All news with #gitlab tag

17 articles

GitLab critical code injection exploited rapidly

πŸ›‘οΈ A critical GitLab vulnerability, CVE-2026-19478 (CVSS 9.4), enables unauthenticated code injection allowing modification or deletion of public projects under certain conditions. Affected CE and EE versions include 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. GitLab released fixes in patched releases, while watchTowr reports rapid in-the-wild exploitation and reproduction using probes targeting GraphQL directives.
read more β†’

Critical GitLab vulnerability allows repo deletion

πŸ”’ GitLab patched a critical code-injection vulnerability in its GraphQL directive that could let unauthenticated attackers modify or delete repositories with a single HTTP request. The update also fixes a high-risk CSRF flaw in the GraphQL multiplex handler. GitLab released multiple patched CE and EE versions and advises administrators to restrict access to /api/graphql and make repos private until updates are applied.
read more β†’

Critical GitLab GraphQL Flaw Allows Remote Project Changes

πŸ”’ GitLab released out-of-cycle security updates on August 17, 2026, to fix a critical GraphQL vulnerability (CVE-2026-19478) that could let unauthenticated attackers remotely modify or delete public projects and user data. The patches apply to self-managed instances in versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4; hosted GitLab.com and Dedicated are already patched. A second, High-severity issue (CVE-2026-19650) addresses a CSRF-related GraphQL multiplex handling flaw requiring user interaction.
read more β†’

Critical Gitea file-read flaw patched in 1.27.1

πŸ”’ An unauthenticated attacker could read any file the Gitea service account can access in versions 1.22.1–1.27.0 by posting crafted Org-mode markup to the markup endpoint. The issue, tracked as CVE-2026-59774 and rated Critical (CVSS 9.8), was fixed in Gitea 1.27.1. Self-hosted admins should upgrade immediately and rotate exposed credentials if the endpoint was reached.
read more β†’

AWS Transform Continuous Modernization Now Generally Available

πŸ” AWS Transform continuous modernization is now generally available in all Regions that support AWS Transform. It enables engineering teams to analyze and remediate technical debt across GitHub, GitLab, and Bitbucket repositories at scale, with on-demand or scheduled analyses and prioritization across technical debt, security, agentic readiness, modernization readiness, and custom criteria. Users can create remediations that open pull requests or merge requests, run analyses in their AWS account, and maintain control of source code. Additional workflows are supported via the AWS Transform Kiro Power, agent plugins, and CLI for IDE and terminal use, local analysis, and remote execution on Amazon EC2 or AWS Batch.
read more β†’

Critical Gitea RCE in diffpatch fixed in 1.27.1

πŸ”’ Gitea patched a critical remote code execution (RCE) vulnerability tracked as CVE-2026-60004 affecting versions 1.17 through 1.27.0. A user with repository write access could craft a malicious patch that becomes an active Git hook and executes shell commands as the Gitea service account. The flaw requires authentication and write permission, but default open registration allows outsiders to create accounts and exploit unpatched instances. Upgrading to 1.27.1 addresses the issue; Gitea Cloud upgrades were scheduled automatically.
read more β†’

GitLab RCE exploit published for unpatched instances

πŸ›‘οΈ Security researcher depthfirst published a working exploit on July 24 for a GitLab flaw patched by GitLab on June 10, enabling command execution as the git user on self-managed 18.11.3 servers that haven't updated. The chain abuses two memory-corruption bugs in the Oj Ruby JSON parser via GitLab's notebook diff renderer, allowing authenticated users who can push a project to leak a heap pointer and trigger a payload without admin or CI access. GitLab listed the Oj 3.17.3 bump under bug fixes rather than as a security fix, leaving operators unaware of the urgency; no CVE or CVSS score has been published yet.
read more β†’

Attackers exploit trusted AI platforms and ads

πŸ” Threat actors abused trusted services β€” Google Ads, GitLab Pages, and Claude’s shared-chat feature β€” to trick developers into executing malicious PowerShell and terminal commands via ClickFix social engineering. Researchers at TrendAI observed a six-wave campaign that funnelled over 2,000 victims from sponsored search results to malicious pages and then to weaponized Claude shared chats. By impersonating popular developer tools and brands, the attackers leveraged reputation stacking to make their lures appear legitimate and evade detection.
read more β†’

CISA Alerts on Five-Year-Old GitLab SSRF Exploitation

⚠️ CISA has ordered federal agencies to patch a five-year-old GitLab SSRF vulnerability (CVE-2021-39935) that is currently being exploited in attacks. GitLab issued a fix for the server-side request forgery bug in December 2021 after it was found that unauthenticated users could reach the CI Lint API when user registration was restricted. Under BOD 22-01, affected Federal Civilian Executive Branch agencies must remediate by February 24, 2026, and CISA urges all organizations to prioritize mitigation. Shodan currently identifies over 49,000 internet-exposed GitLab instances, many reachable on default ports.
read more β†’

GitLab 2FA Bypass Vulnerability Requires Immediate Patch

πŸ”’ A critical two-factor authentication bypass (CVE-2026-0723) in GitLab Community and Enterprise editions allows an attacker who knows a user’s credentials to submit forged device responses and bypass MFA. GitLab released patches in versions 18.8.2, 18.7.2 and 18.6.4 and strongly recommends that all self-managed instances upgrade immediately. Additional fixes address several denial-of-service and authorization flaws; GitLab.com and Dedicated tenants are already protected.
read more β†’

Zoom and GitLab Release Patches for Critical Flaws

πŸ”’ Zoom and GitLab released security updates to address multiple vulnerabilities that could enable denial-of-service, remote code execution, and a two-factor authentication bypass. The most severe is a critical command injection in Zoom Node Multimedia Routers (CVE-2026-22844, CVSS 9.9) that may allow remote code execution; Zoom reports no evidence of active exploitation. GitLab patched several high-severity DoS and 2FA-bypass issues across CE and EE releases. Administrators should apply the provided patches, upgrade affected modules, and review exposure to untrusted networks immediately.
read more β†’

GitLab warns of 2FA bypass and multiple DoS vulnerabilities

πŸ”’ GitLab has patched a high-severity two-factor authentication bypass (CVE-2026-0723) that could allow attackers who know a target's account ID to submit forged device responses and bypass 2FA. The release also addresses two high-severity denial-of-service flaws (CVE-2025-13927, CVE-2025-13928) and two medium-severity DoS issues affecting Wiki rendering and SSH authentication. Administrators should upgrade to 18.8.2, 18.7.2, or 18.6.4 immediately; GitLab.com is already patched.
read more β†’

Hidden Risks in DevOps Stacks and Data Protection Strategies

πŸ”’ DevOps platforms like GitHub, GitLab, Bitbucket, and Azure DevOps accelerate development but also introduce data risks from misconfigurations, exposed credentials, and service outages. Under the SaaS shared responsibility model, customers retain liability for protecting repository data and must enforce MFA, RBAC, and tested backups. Third-party immutable backups and left-shifted security practices are recommended to mitigate ransomware, insider threats, and accidental deletions.
read more β†’

SBOM Implementation: Eight Best Tools for Supply Chains

πŸ” To secure modern software you must know what's inside it, and a Software Bill of Materials (SBOM) provides that transparency. An SBOM should be machine-readable, include component, version, license and patch data, and be generated automatically in CI/CD using standards like SPDX, CycloneDX or SWID. The article reviews eight tools β€” including Anchore, FOSSA, GitLab and Mend β€” that generate, analyze and manage SBOMs across the build, registry and runtime lifecycles.
read more β†’

Red Hat Confirms GitLab Breach Affecting Consulting

πŸ”’ Red Hat confirmed a security incident after an extortion group calling itself the Crimson Collective claimed to have stolen nearly 570GB of compressed data from roughly 28,000 internal repositories in a GitLab instance used solely for consulting engagements. The group alleges the haul includes about 800 Customer Engagement Reports (CERs) that may contain infrastructure details, authentication tokens, and database URIs. Red Hat says it is remediating the issue, has not verified the attackers' specific claims, and believes its software supply chain and other services remain unaffected.
read more β†’

Max Severity Argo CD API Flaw Exposes Repo Credentials

πŸ”’ A critical Argo CD vulnerability (CVE-2025-55190) allows API tokens with even low project-level get permissions to access API endpoints and retrieve repository credentials. Rated CVSS v3 10.0, the flaw bypasses isolation protections and can expose usernames and passwords used to access Git repositories. The issue affects all versions up to 2.13.0 and was fixed in 3.1.2, 3.0.14, 2.14.16, and 2.13.9; administrators should upgrade immediately.
read more β†’

AggregateIQ Code Leak Exposes Political Targeting Tools

πŸ”“ UpGuard disclosed that a large GitLab repository belonging to AggregateIQ was publicly accessible, exposing source code, configuration files, and numerous credentials. The leak included applications and tools β€” notably projects named Ripon_canvas and Ripon_dialer β€” designed to manage voter databases, microtargeting, canvassing, and automated outreach. Credentials for Facebook apps, Twilio, AWS, and other services were present, raising the risk of account takeover and large-scale data harvesting. UpGuard linked the repository to work for US campaigns and reported ties to Cambridge Analytica, with further technical analysis promised in subsequent reports.
read more β†’