⤷ Title: GitLab Security Update: High-Severity Vulnerabilities Patched in April Release
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 12:30:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_4922 #CVE_2026_5816 #DevSecOps #gitlab #GraphQL API #infosec #Patch Alert #security update #Session Hijacking #Web IDE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 12:30:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_4922 #CVE_2026_5816 #DevSecOps #gitlab #GraphQL API #infosec #Patch Alert #security update #Session Hijacking #Web IDE
Daily CyberSecurity
GitLab Security Update: High-Severity Vulnerabilities Patched in April Release
GitLab fixes high-severity GraphQL CSRF and Web IDE vulnerabilities in versions 18.11.1, 18.10.4, and 18.9.6. Protect your sessions and projects—patch now!
⤷ Title: Supply Chains in the Crosshairs: Scan and Simulate Multi-Stage Attacks with Trajan
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 08:24:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Azure DevOps #CI/CD Security #DevSecOps #GitHub Actions #GitLab CI #jenkins #JFrog #Pentesting Tools #supply chain attack #Taint Tracking #Trajan #WebAssembly
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 08:24:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Azure DevOps #CI/CD Security #DevSecOps #GitHub Actions #GitLab CI #jenkins #JFrog #Pentesting Tools #supply chain attack #Taint Tracking #Trajan #WebAssembly
Penetration Testing Tools
Supply Chains in the Crosshairs: Scan and Simulate Multi-Stage Attacks with Trajan
Trajan isn't just a scanner. It maps dependency graphs and uses built-in attack plugins to simulate real-world CI/CD supply chain compromises.
⤷ Title: GitLab Critical Patch: High-Severity XSS and Unauthenticated DoS Flaws Hit Self-Managed Instances
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:39:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CE #CVE_2026_7481 #Cyber Security #DevOps Security #dos #EE #gitlab #GitLab 18.11.3 #GitLab Security Patch #infosec #Patch Alert #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:39:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CE #CVE_2026_7481 #Cyber Security #DevOps Security #dos #EE #gitlab #GitLab 18.11.3 #GitLab Security Patch #infosec #Patch Alert #XSS
Daily CyberSecurity
GitLab Critical Patch: High-Severity XSS and Unauthenticated DoS Flaws Hit Self-Managed Instances
GitLab patches high-severity XSS (8.7 CVSS) and unauthenticated DoS flaws in versions 18.11.3, 18.10.6, and 18.9.7. Secure your DevOps pipeline now!
⤷ Title: Velvet Chollima Leaves Backend Keys Inside Critical GitLab Dead-Drop Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:16:41 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #cyber_espionage #EV Code Signing #GitLab Dead_Drop #infosec #Keylogger #Malware Analysis #OPSEC Failure #threat intelligence #Tralert FX #Velvet Chollima
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:16:41 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #cyber_espionage #EV Code Signing #GitLab Dead_Drop #infosec #Keylogger #Malware Analysis #OPSEC Failure #threat intelligence #Tralert FX #Velvet Chollima
Daily CyberSecurity
Velvet Chollima Leaves Backend Keys Inside Critical GitLab Dead-Drop Malware
A routine investigation into a low-detection installer has blown the doors off a highly organized, financially motivated cyber-espionage campaign. Orchestrated by a single operator or small team l…
⤷ Title: New GitLab Security Updates Fix Critical Flaws in Duo AI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 00:14:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Security #CVE_2026_4868 #Duo AI Workflows #GitLab CE #GitLab EE #GitLab Patch #SecOps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 00:14:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Security #CVE_2026_4868 #Duo AI Workflows #GitLab CE #GitLab EE #GitLab Patch #SecOps
Daily CyberSecurity
New GitLab Security Updates Fix Critical Flaws in Duo AI
The latest GitLab security updates address high-severity bugs. Download the patch to ensure the Duo AI flaw fixed protects your DevSecOps pipeline.
⤷ Title: Auditing GitLab: The CI/CD Kill Chain
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 12:00:00 +0000
════════════════════════
⌗ Tags: #Blue Team Tools #External/Internal #InfoSec 301 #Recon #Red Team #Red Team Tools #attacking #cicd #Defending #devops #GitLab #gogatoz #Phil Miller
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 12:00:00 +0000
════════════════════════
⌗ Tags: #Blue Team Tools #External/Internal #InfoSec 301 #Recon #Red Team #Red Team Tools #attacking #cicd #Defending #devops #GitLab #gogatoz #Phil Miller
Black Hills Information Security, Inc.
Auditing GitLab: The CI/CD Kill Chain - Black Hills Information Security, Inc.
Welcome to GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain along with everything those one-off scripts did and then some.
⤷ Title: Non-group members can be added to projects even though the “Users cannot be added to projects in…
════════════════════════
𐀪 Author: Rohmad Hidayah
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 12:31:47 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #business_logic_flaw #gitlab
════════════════════════
𐀪 Author: Rohmad Hidayah
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 12:31:47 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #business_logic_flaw #gitlab
Medium
Non-group members can be added to projects even though the “Users cannot be added to projects in…
https://gitlab.com/gitlab-org/gitlab/-/work_items/551267
⤷ Title: Important GitLab Security Updates Address 12 Vulnerabilities
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 02:24:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_10087 #CVE_2026_10733 #CVE_2026_1500 #CVE_2026_3553 #CVE_2026_6269 #CVE_2026_6277 #CVE_2026_6552 #CVE_2026_6976 #CVE_2026_7250 #CVE_2026_8589 #CVE_2026_9204 #CVE_2026_9694 #cybersecurity #gitlab
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 02:24:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_10087 #CVE_2026_10733 #CVE_2026_1500 #CVE_2026_3553 #CVE_2026_6269 #CVE_2026_6277 #CVE_2026_6552 #CVE_2026_6976 #CVE_2026_7250 #CVE_2026_8589 #CVE_2026_9204 #CVE_2026_9694 #cybersecurity #gitlab
Daily CyberSecurity
Important GitLab Security Updates Address 12 Vulnerabilities
Discover the latest GitLab security updates in patch release 19.0.2. Protect your self-managed servers from critical vulnerabilities like CVE-2026-6552.
⤷ Title: GitLab Security Updates Fix 13 Flaws
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 07:41:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_10086 #CVE_2026_10712 #CVE_2026_12053 #gitlab #Patch Release
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 07:41:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_10086 #CVE_2026_10712 #CVE_2026_12053 #gitlab #Patch Release
Daily CyberSecurity
GitLab Security Updates Fix 13 Flaws
GitLab released critical security updates addressing 13 vulnerabilities, including severe cross-site scripting and information disclosure flaws.
⤷ Title: GitLab Addresses Critical Security Flaws: A Reminder of the Importance of Secure Development…
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 11:52:41 GMT
════════════════════════
⌗ Tags: #software_security #devseops #gitlab #application_security #cybersecurity
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 11:52:41 GMT
════════════════════════
⌗ Tags: #software_security #devseops #gitlab #application_security #cybersecurity
Medium
GitLab Addresses Critical Security Flaws: A Reminder of the Importance of Secure Development…
Organizations worldwide rely on GitLab to manage software development, collaboration, and DevSecOps workflows. Recently, GitLab released…
⤷ Title: CVE-2026–10087: Cross-Site Scripting in GitLab EE Analytics Dashboard
════════════════════════
𐀪 Author: CyberPodcast
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 13:01:02 GMT
════════════════════════
⌗ Tags: #web_application_security #xss_vulnerability #cve #application_security #gitlab
════════════════════════
𐀪 Author: CyberPodcast
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 13:01:02 GMT
════════════════════════
⌗ Tags: #web_application_security #xss_vulnerability #cve #application_security #gitlab
Medium
CVE-2026–10087: Cross-Site Scripting in GitLab EE Analytics Dashboard
When analytics dashboards become a client-side execution surface
⤷ Title: GitLab Patch Release Fixes Eight Flaws, Including a High-Severity XSS Bug (CVE-2026-6896)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 02:15:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_13320 #CVE_2026_6896 #DevSecOps #GitLab EE #GitLab patch release #HTML Injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 02:15:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_13320 #CVE_2026_6896 #DevSecOps #GitLab EE #GitLab patch release #HTML Injection
Daily CyberSecurity
GitLab Patch Release Fixes Eight Flaws, Including a High-Severity XSS Bug (CVE-2026-6896)
TL;DR This GitLab patch release, shipped on July 8, 2026, covers versions 19.1.2, 19.0.4, and 18.11.7. The update fixes eight security flaws across Community and Enterprise Edition. The most sever…
⤷ Title: GitLab RCE Vulnerability Explained: The Notebook Diff Exploit Chain
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 12:57:44 GMT
════════════════════════
⌗ Tags: #gitlab #infosec #devsecops #cybersecurity #vulnerability
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 12:57:44 GMT
════════════════════════
⌗ Tags: #gitlab #infosec #devsecops #cybersecurity #vulnerability
Medium
GitLab RCE Vulnerability Explained: The Notebook Diff Exploit Chain
GitLab just patched a remote code execution vulnerability that never got a CVE, never got a security advisory, and was triggered by…
⤷ Title: Critical GitLab RCE Vulnerability Exposed in Oj JSON Parser
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:00:55 +0000
════════════════════════
⌗ Tags: #Vulnerability #Gitlab #Jupyter Notebook #Oj Parser #remote code execution #vulnerability
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:00:55 +0000
════════════════════════
⌗ Tags: #Vulnerability #Gitlab #Jupyter Notebook #Oj Parser #remote code execution #vulnerability
Information Security News
Critical GitLab RCE Vulnerability Exposed in Oj JSON Parser
Unmasking the Concealed Remote Code Execution Flaw A critical remote code execution (RCE) flaw in self-hosted GitLab installations lay concealed for nearly six weeks. Although GitLab patched the u…
⤷ Title: GitLab Patch Release Fixes 13 Security Vulnerabilities
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 03:10:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12436 #CVE_2026_6267 #DevSecOps #gitlab #GitLab Duo #GitLab patch release
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 03:10:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12436 #CVE_2026_6267 #DevSecOps #gitlab #GitLab Duo #GitLab patch release
Daily CyberSecurity
GitLab Patch Release Fixes 13 Security Vulnerabilities
TL;DR GitLab has shipped a new patch release for self-managed installs. Versions 19.2.1, 19.1.3, and 19.0.5 fix 13 security vulnerabilities. The most serious is a high-severity data exposure bug r…
⤷ Title: Public PoC Exploits GitLab RCE via Two Oj Memory Corruption Bugs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 07:30:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #depthfirst #gitlab #GitLab RCE #ipynbdiff #memory corruption #Oj #proof_of_concept #Remote Code Execution #Ruby
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 07:30:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #depthfirst #gitlab #GitLab RCE #ipynbdiff #memory corruption #Oj #proof_of_concept #Remote Code Execution #Ruby
Daily CyberSecurity
Public PoC Exploits GitLab RCE via Two Oj Memory Corruption Bugs
TL;DR: Researchers at depthfirst released a working proof-of-concept for a GitLab RCE that runs commands as the git user. The chain abuses two memory corruption bugs in Oj, a native Ruby JSON pars…
⤷ Title: GitLab Patch Release Fixes 13 Flaws, Including High-Severity XSS Bugs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 23:57:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_15217 #CVE_2026_15423 #DevSecOps #gitlab #GitLab patch release #XSS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 23:57:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_15217 #CVE_2026_15423 #DevSecOps #gitlab #GitLab patch release #XSS
Daily CyberSecurity
GitLab Patch Release Fixes 13 Flaws, Including High-Severity XSS Bugs
TL;DR GitLab shipped a new patch release on August 12, 2026. Versions 19.2.2, 19.1.4, and 19.0.6 fix 13 security flaws across Community and Enterprise Edition. The most severe are high-rated cross…
⤷ Title: CVE-2026-19478 (CVSS 9.4): GitLab GraphQL Code Injection Flaw Patched
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 01:40:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #code_injection #CSRF #CVE_2026_19478 #CVE_2026_19650 #gitlab #graphql
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 01:40:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #code_injection #CSRF #CVE_2026_19478 #CVE_2026_19650 #gitlab #graphql
Daily CyberSecurity
CVE-2026-19478 (CVSS 9.4): GitLab GraphQL Code Injection Flaw Patched
TL;DR GitLab shipped an out-of-band critical patch on August 17, 2026. It fixes CVE-2026-19478, a GraphQL code injection flaw rated CVSS 9.4. Under certain conditions, an unauthenticated attacker …
⤷ Title: Critical GitLab Flaw Exploited Shortly After Disclosure
════════════════════════
𐀪 Author: Ionut Arghire
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:48:24 +0000
════════════════════════
⌗ Tags: #Vulnerabilities #exploited #GitLab #vulnerability
════════════════════════
𐀪 Author: Ionut Arghire
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:48:24 +0000
════════════════════════
⌗ Tags: #Vulnerabilities #exploited #GitLab #vulnerability
SecurityWeek
Critical GitLab Flaw Exploited Shortly After Disclosure
CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data.