Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
GitLab

GitLab Vendor Cyber Rating & Cyber Score

gitlab.com

GitLab is the Intelligent Orchestration Platform where software teams and their AI agents stay in flow to amplify their capacity for innovation. Together, they automate repetitive tasks to plan, build, secure, test, deploy and maintain software. With GitLab, software teams spend less time on coordination overhead and more time on the next big idea. GitLab Duo Agent Platform provides AI agents that automate tasks across the software lifecycle. Agents handle code generation, security analysis, code review, CI/CD troubleshooting, and custom workflows — while teams maintain control through enterprise governance. Build what's next with us. Explore open roles and join our talent community: https://about.gitlab.com/jobs/


GitLab A.I CyberSecurity Scoring

GitLab
Company Information
Website:https://about.gitlab.com/?utm_medium=social&utm_source=linkedin&utm_campaign=profile
Employees number:3,422
Number of followers:1,162,783
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:gitlab.com
GitLab Risk Score (AI oriented)
Between 700 and 749
logo
GitLabIT Services and IT Consulting
Updated:
06/10/2026
728/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
GitLab Global Score (TPRM)
xxxx
logo
GitLabIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

GitLabModerate
Current Score
728Ba (MODERATE)
01000
14 incidents
-6 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
734Before Incident
Vulnerability
06 Oct 2026 • GitLab
GitLab: Gentlemen Ransomware Affiliate Uses Stolen GitLab CI/CD Secrets to Breach Dozens of Organizations

Russian Ransomware Affiliate Exploits GitLab Vulnerabilities in Multi-Country Cyberattacks

728After Incident
CRITICAL-6
GIT1791282399
Russian Ransomware Affiliate Exploits GitLab Vulnerabilities in Multi-Country Cyberattacks A Russian-speaking threat actor, operating under the alias Azazel, has been identified as an affiliate of the Gentlemen ransomware group while simultaneously running an independent extortion operation via the LEAKNED data leak site. Researchers from CloudSEK uncovered a series of breaches affecting over two dozen organizations across six countries, spanning sectors including logistics, insurance, pharmaceuticals, AI, medical devices, and government-linked services. The attacks primarily exploited exposed credentials in GitLab pipelines, configuration files, and repository histories. Using tools like glato, nord-stream, gitlab-secrets, and gitleaks, Azazel harvested sensitive data, including database passwords, API keys, access tokens, and SSH private keys. These credentials enabled lateral movement from development environments into production systems, with one compromised GitLab instance exposing multiple unrelated organizations. In one case, a single pipeline token granted access to database credentials, shipping service logins, and private keys for three cloud servers. Another breach spread from a software platform to over a dozen customer environments, compromising 150+ databases, payment gateways, and hundreds of source code repositories. A government-linked financial registry lost over 120,000 records, with Azazel deploying a Python script to delete PostgreSQL production data after exfiltration. The attacker also embedded ransom messages across SSH banners, database settings, GitLab projects, and admin login pages. In a separate attack on an AI platform, an unvalidated imaging API allowed server-side request forgery (SSRF), enabling access to internal services. Azazel decrypted protected configurations using a recovered Jasypt master key, extracted Grafana admin hashes, and exfiltrated over six terabytes of data including Kubernetes configs, SSH keys, and credentials via continuous object storage transfers. Further investigation revealed the use of Model Context Protocol (MCP) for internal command execution, with scripts automating ransom message delivery across six hosts. The attacker’s infrastructure, split across three servers, boasted over 50 terabytes of storage, with MEGA serving as a final transfer destination. Evidence also suggested the use of an AI assistant for attack planning. CloudSEK’s findings highlight a sophisticated campaign combining credential theft, data destruction, and AI-assisted operations, though no direct targeting of U.S. military infrastructure was confirmed. The exposed infrastructure provided rare insight into an active ransomware affiliate’s workflow.
INCIDENT DETAILS -
TYPE
ransomwaredata breachextortion
MOTIVATION
financial gaindata extortiondisruption
IMPACT
Data Compromised: Over six terabytes of data exfiltrated, including database credentials, API keys, SSH keys, Kubernetes configs, and source code repositoriesGitLab instancesproduction databasescloud serverspayment gatewaysinternal servicesOperational Impact: Data destruction (e.g., PostgreSQL production data deleted), lateral movement into production systems, ransom messages embedded in SSH banners and admin login pagesBrand Reputation Impact: Likely significant due to data breaches and extortionIdentity Theft Risk: High (PII and credentials exposed)Payment Information Risk: High (payment gateways compromised)
DATA BREACH
database credentialsAPI keysaccess tokensSSH private keysKubernetes configssource code repositoriesGrafana admin hashespayment gateway loginsPII (120,000+ records)Number Of Records Exposed: 120,000+ (government-linked financial registry), 150+ databases, hundreds of source code repositoriesSensitivity Of Data: High (PII, financial data, credentials, proprietary code)Data Exfiltration: Yes (over six terabytes, including via MEGA)Data Encryption: Yes (ransomware encryption, Jasypt master key decryption)configuration filessource codedatabase dumpsSSH keysKubernetes configsPersonally Identifiable Information: Yes (120,000+ records)
SEPTEMBER 2026
737Before Incident
Vulnerability
23 Sep 2026 • GitLab
GitLab: GitLab Email Feature Vulnerability Lets Attackers Push Code Into Private Repositories

GitLab Email Feature Exploited as Repository Compromise Vector

733After Incident
CRITICAL-4
GIT1790180743
GitLab Email Feature Exploited as Repository Compromise Vector On September 23, 2026, security researcher Joe Leon of Aikido Security disclosed a critical flaw in GitLab’s "Email work item to this project" feature, which could allow attackers to compromise repositories if the private incoming-email address is exposed. The vulnerability stems from a long-lived glimt- token embedded in the address, which GitLab confirms does not expire and must remain confidential. The issue extends beyond spam: while the feature appears project-specific, Aikido found that addresses across different projects share the same account-level token. Attackers can manipulate the email subject to replace -issue with -merge-request, attach a malicious Git patch, and execute it under the victim’s permissions. This could lead to unauthorized commits, including to protected branches like main, with actions appearing under the compromised user’s identity. A particularly concerning finding is that GitLab’s IP restrictions intended to limit access do not apply to incoming emails. Aikido demonstrated that even when a private project was configured to accept only a specific IP, GitLab still processed emailed patches, bypassing network controls. GitLab has since updated its documentation to clarify that incoming email is exempt from IP allowlists. Exploitation requires the private address and basic project details (e.g., path and ID), which are publicly available for open repositories. For private projects, attackers would need additional leaked information. Notably, GitLab does not verify that emails originate from the token owner’s account, though the company has opened an issue to explore such validation. GitLab has addressed the disclosure by updating its interface and documentation to emphasize token secrecy, reset procedures, and the risks of merge requests via email. However, the underlying email mechanism remains unchanged. Organizations are advised to audit repositories, logs, and public-facing assets for exposed glimt- addresses and reset tokens if compromised, as well as review affected users’ permissions and pipeline configurations.
INCIDENT DETAILS -
TYPE
Repository Compromise
IMPACT
Data Compromised: Repository code and configurationsSystems Affected: GitLab repositories (public and private)Operational Impact: Unauthorized code changes, potential pipeline disruptions, and compromised user permissionsBrand Reputation Impact: Moderate (public disclosure of vulnerability, potential misuse of compromised repositories)Identity Theft Risk: Low (user identities could be impersonated for commits)
DATA BREACH
Type Of Data Compromised: Repository code, configurations, and potentially sensitive project detailsSensitivity Of Data: Moderate to High (depends on repository contents)File Types Exposed: Git patches, repository filesPersonally Identifiable Information: User identities (commit authorship)
SEPTEMBER 2026
741Before Incident
Vulnerability
10 Sep 2026 • GitLab
GitLab: Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

GitLab Patches Critical Vulnerabilities in Emergency Security Update

737After Incident
CRITICAL-4
GIT1789130145
GitLab Patches Critical Vulnerabilities in Emergency Security Update GitLab released an emergency security update on September 10, 2026, addressing two critical vulnerabilities and a high-severity flaw that could lead to unauthenticated file disclosure, credential theft, and remote code execution (RCE). The patched versions 19.3.2, 19.2.6, and 19.1.8 apply to GitLab Community Edition (CE) and Enterprise Edition (EE). While GitLab.com has already been updated, self-managed instances must be upgraded immediately. GitLab Dedicated customers require no action. ### Critical Vulnerabilities 1. CVE-2026-85706 (CVSS 10.0) – A path-traversal flaw in the repository commits API allows unauthenticated attackers to read arbitrary files from GitLab servers, potentially exposing secrets, tokens, and configuration data. This affects CE/EE versions 18.7 and later. 2. CVE-2026-87719 (CVSS 9.9) – An authenticated GraphQL subscription flaw in GitLab EE (18.3+) could let attackers bypass serialization controls, accessing Advanced Search configurations and sensitive credentials. ### High-Severity RCE Risk - CVE-2026-88765 (CVSS 8.5) – A buffer overflow in Unicode conversion during Advanced Search indexing could allow authenticated users to trigger RCE via a maliciously crafted Git project export. This affects EE versions 12.3 and later. ### Additional Fixes The update also resolves: - Protected CI/CD variable exposure - SAML SSO bypasses - Stored/reflected XSS vulnerabilities - Package registry tampering risks - GraphQL denial-of-service (DoS) flaws ### Affected Versions & Mitigation Administrators should upgrade to the latest patched versions: - 19.3 → 19.3.2 - 19.2 → 19.2.6 - 19.1 → 19.1.8 Security teams are advised to review logs for suspicious activity, including API calls, project imports, and GraphQL requests. Older unsupported branches should transition to a patched release as soon as possible.
INCIDENT DETAILS -
TYPE
Data BreachRemote Code ExecutionPrivilege Escalation
IMPACT
SecretsTokensConfiguration DataCredentialsProtected CI/CD VariablesGitLab Community Edition (CE)GitLab Enterprise Edition (EE)Self-managed GitLab instancesOperational Impact: Potential unauthorized access and remote code execution on affected systemsBrand Reputation Impact: Potential reputational damage due to critical vulnerabilitiesIdentity Theft Risk: High (due to credential theft and PII exposure)
DATA BREACH
SecretsTokensConfiguration DataCredentialsProtected CI/CD VariablesSensitivity Of Data: High (secrets, tokens, credentials)Data Exfiltration: Possible via path-traversal flaw (CVE-2026-85706)
SEPTEMBER 2026
745Before Incident
Vulnerability
01 Sep 2026 • GitLab
GitLab: GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab Urges Immediate Patch for Critical AI Gateway Vulnerability (CVE-2026-90970)

740After Incident
CRITICAL-5
GIT1790965437
GitLab Urges Immediate Patch for Critical AI Gateway Vulnerability (CVE-2026-90970) GitLab has issued an urgent security advisory warning customers to patch a critical vulnerability in its AI Gateway service, which could allow attackers to execute arbitrary commands on unpatched instances. The flaw, tracked as CVE-2026-90970, affects self-hosted AI Gateway deployments on GitLab Self-Managed and stems from an improper neutralization weakness in the prompt template sandbox. An authenticated user with Duo Agent Platform access could exploit the vulnerability by crafting a malicious flow configuration, bypassing security controls and gaining command execution on the AI Gateway. GitLab has released fixes in versions 19.2.4, 19.3.2, and 19.4.1, urging all self-hosted AI Gateway users to upgrade immediately. Customers using GitLab’s cloud-hosted AI Gateway are unaffected and require no action. The company disclosed the vulnerability on Friday, following targeted outreach to self-hosted AI Gateway customers prior to public release. This follows another recent critical patch CVE-2026-85706, a maximum-severity path traversal flaw in GitLab Community and Enterprise Editions exploited in the wild to extract sensitive data. CISA added the latter to its Known Exploited Vulnerabilities Catalog, mandating federal agencies to remediate within three days under Binding Operational Directive 26-04. GitLab’s platform, used by over 30 million users and 50% of Fortune 100 companies, has faced repeated exploitation, including attacks by ransomware groups. Since 2021, CISA has flagged five GitLab vulnerabilities actively abused in the wild.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Systems Affected: GitLab Self-Managed AI Gateway deploymentsOperational Impact: Arbitrary command execution on unpatched instances
AUGUST 2026
748Before Incident
Vulnerability
17 Aug 2026 • GitLab
GitLab: GitLab Critical Vulnerability Lets Unauthenticated Attackers Modify or Delete Projects

GitLab Patches Critical Vulnerability Allowing Unauthenticated Data Tampering

744After Incident
CRITICAL-4
GIT1787036383
GitLab Patches Critical Vulnerability Allowing Unauthenticated Data Tampering GitLab released emergency security updates on August 17, 2026, addressing a critical vulnerability (CVE-2026-19478) that could enable unauthenticated attackers to remotely modify or delete public projects and user data. The flaw, rated 9.4 on the CVSS scale, affects GitLab Community Edition (CE) and Enterprise Edition (EE) across multiple versions, including 18.2–18.11.11, 19.0.0–19.0.8, 19.1.0–19.1.6, and 19.2.0–19.2.4. The issue stems from a code injection vulnerability in a GraphQL directive, allowing remote exploitation without credentials or user interaction. Organizations with internet-facing GitLab instances, public repositories, or exposed GraphQL services are at heightened risk, as attackers could disrupt development workflows, tamper with source code, or compromise downstream supply chains. GitLab also patched a second, high-severity flaw (CVE-2026-19650, CVSS 7.1), a CSRF vulnerability in the GraphQL multiplex query handler. This could allow unauthenticated users to execute unauthorized state-changing operations via crafted GET requests, though exploitation requires user interaction. Patched versions (19.2.4, 19.1.6, 19.0.8, and 18.11.11) were released outside GitLab’s standard update cycle. GitLab Dedicated customers are unaffected, as their hosted instances were automatically updated. Self-managed administrators are advised to apply fixes immediately, noting that Omnibus packages may trigger service restarts unless configured for zero-downtime upgrades. The vulnerabilities underscore risks in GraphQL request handling, particularly when exposed interfaces permit sensitive actions. Organizations are encouraged to review audit logs for suspicious activity, verify backups, and ensure proper access controls.
INCIDENT DETAILS -
TYPE
Code InjectionCSRF
IMPACT
Public projectsUser dataGitLab Community Edition (CE)GitLab Enterprise Edition (EE)Disruption of development workflowsTampering with source codeCompromise of downstream supply chains
DATA BREACH
Public projectsUser data
JULY 2026
752Before Incident
Vulnerability
29 Jul 2026 • GitLab
GitLab: GitLab Fixes 13 Security Flaws That Can Leak Data, Alter Pipelines, and Crash Servers

GitLab Patches 13 Critical Vulnerabilities in July 2026 Security Update

747After Incident
CRITICAL-5
GIT1785407607
GitLab Patches 13 Critical Vulnerabilities in July 2026 Security Update GitLab released critical security updates on July 29, 2026, addressing 13 vulnerabilities in its Community Edition (CE) and Enterprise Edition (EE) deployments. The patches versions 19.2.1, 19.1.3, and 19.0.5 resolve high-, medium-, and low-severity flaws that could expose sensitive data, manipulate CI/CD pipelines, and disrupt server availability. ### Key Vulnerabilities Fixed Among the most severe issues: - CVE-2026-6267 (CVSS 8.5): A high-severity flaw in GitLab Workhorse allowing authenticated Developer-level users to access sensitive internal data due to improper access controls. - CVE-2026-12436: A mass-assignment vulnerability in the Pipeline Schedule API, enabling attackers to modify other users’ CI/CD configurations, potentially leading to unauthorized pipeline executions. - CVE-2026-15975: A denial-of-service (DoS) vulnerability in merge request discussions, exploitable by unauthenticated attackers to crash or degrade server performance. Additional medium-severity flaws include: - Race conditions in merge request approval rules, risking unauthorized code merges into protected branches. - Improper authorization in project imports, pipeline test reports, and merge request metadata, exposing confidential data. - Cross-site scripting (XSS) and prompt injection vulnerabilities in GitLab Duo AI-assisted tools, highlighting emerging risks in AI-driven development. ### Potential Attack Scenarios A low-privilege developer could exploit the Pipeline Schedule API flaw to inject malicious scripts into CI/CD pipelines, leading to supply chain compromise, unauthorized deployments, or data exfiltration without detection. ### Patch Deployment & Impact - GitLab.com and GitLab Dedicated users are already protected. - Self-managed users must upgrade immediately, as patches include database migrations that may cause downtime for single-node deployments. - Multi-node environments can apply updates with zero-downtime procedures. GitLab will publicly disclose all vulnerabilities 90 days post-patch, following responsible disclosure practices. The company emphasized the urgency of updates to secure code repositories and development workflows.
INCIDENT DETAILS -
TYPE
Vulnerability Disclosure
IMPACT
Sensitive internal dataCI/CD configurationsConfidential project dataMerge request metadataGitLab WorkhorsePipeline Schedule APIMerge request discussionsGitLab Duo AI toolsDowntime: Potential downtime for single-node deployments during database migrationsUnauthorized pipeline executionsSupply chain compromiseServer performance degradation or crashBrand Reputation Impact: Potential impact due to exposure of sensitive data and pipeline manipulation
DATA BREACH
Sensitive internal dataCI/CD configurationsConfidential project dataMerge request metadataSensitivity Of Data: HighData Exfiltration: Potential via CI/CD pipeline manipulation
JUNE 2026
750Before Incident
MAY 2026
753Before Incident
Vulnerability
21 May 2026 • GitLab
GitLab: Two Old Oj Flaws Chained to Trigger GitLab Remote Code Execution

Critical GitLab RCE Vulnerability Exploits Ruby JSON Parser Flaws

749After Incident
CRITICAL-4
GIT1785155190
Critical GitLab RCE Vulnerability Exploits Ruby JSON Parser Flaws A newly disclosed vulnerability in GitLab allows remote code execution (RCE) by chaining two long-standing memory-safety flaws in the Oj JSON parsing library, a high-performance Ruby dependency. Discovered by Yuhang Wu of the Open Defense Initiative, the exploit targets default GitLab installations, enabling attackers to execute arbitrary commands, access repositories, steal secrets, and compromise internal services. The attack leverages Jupyter Notebook (.ipynb) file processing in GitLab, which uses the ipynbdiff gem to parse notebooks with Oj before displaying differences. By submitting maliciously crafted notebooks in a single commit-diff request, an authenticated user with standard push and diff-view permissions could corrupt memory, bypass Address Space Layout Randomisation (ASLR), and gain code execution as the “git” system user. The vulnerabilities an unchecked nesting-stack write and an unsafe 16-bit key-length narrowing issue had gone undetected for nearly five years. While individually limited, their combination allowed heap manipulation, callback pointer control, and arbitrary command execution. Unlike prior GitLab RCE exploits that relied on SSRF against Redis, this attack bypasses modern protections by targeting a memory-unsafe native dependency in Ruby. Affected Versions & Fixes The flaw impacts GitLab CE/EE versions 15.2.0–18.10.7, 18.11.0–18.11.4, and 19.0.0–19.0.1, with patches released in 18.10.8, 18.11.5, and 19.0.2. The Oj gem (versions 3.13.0–3.17.1) was fixed in 3.17.3. GitLab.com was patched pre-disclosure, while self-managed instances require immediate upgrades. The vulnerabilities were reported on 21 May 2026, with Oj fixes merged on 27 May and released on 4 June. GitLab confirmed and patched the exploit chain by 10 June 2026. The same research also uncovered nine additional CVEs in Oj, including buffer overflows and use-after-free flaws, underscoring risks in memory-unsafe Ruby extensions.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
RepositoriesSecretsGitLab CE/EEOperational Impact: Compromise of internal services
DATA BREACH
RepositoriesSecretsSensitivity Of Data: High.ipynb (Jupyter Notebook)
APRIL 2026
768Before Incident
Cyber Attack
01 Apr 2026 • GitLab
GitLab, Proofpoint, Google, GitHub, Phantom and Firefox: North Korean Hackers Use Fake Coding Tasks to Steal Crypto

North Korean Threat Actor Targets Developers in Large-Scale Phishing Campaign

750After Incident
LOW-18
MOZPHAGITPROGOOGIT1780935989
North Korean Threat Actor Targets Developers in Large-Scale Phishing Campaign A likely North Korean threat actor has conducted a sophisticated phishing campaign, targeting nearly 100 organizations primarily in the U.S. with fake job offers and code-review requests to steal cryptocurrency and credentials. The operation, tracked by Proofpoint as UNK_DeadDrop, sent over 250 malicious emails in April and May 2026, focusing on employees in technology, education, finance, and cryptocurrency firms. ### How the Attack Worked The campaign used shifting pretexts including fake full-stack developer roles, AI payment agent projects, and ERC-4626 smart-contract testing to lure victims into cloning malicious GitHub or GitLab repositories. Once opened in VS Code or Cursor, a hidden tasks.json file executed automatically, exploiting a legitimate editor feature. - VS Code displayed a trust prompt, but Cursor ran the payload silently without user interaction. - The malware installed a fake Google-themed VS Code extension, ensuring persistence by relaunching on macOS and Linux whenever the editor reopened. - Linux/macOS systems received a Go-based remote access trojan (RAT) from the open-source Overlord framework, while Windows ran JavaScript directly in the editor, leaving no disk footprint. ### Data Theft & Wallet Drainage The malware targeted cryptocurrency wallets and browser credentials, including: - Browser extensions: MetaMask, Phantom, Keplr - Desktop wallets: Exodus, Electrum, Ledger Live - Saved passwords & cookies from Chrome, Brave, Edge, and Firefox To bypass security: - macOS/Linux displayed a fake password prompt, using the input to escalate privileges and dump keychains. - Windows bypassed Chrome’s app-bound encryption to extract data. After exfiltration, the malware deleted itself to evade detection. ### Attribution & Distinct Tactics While resembling Contagious Interview a long-running North Korean operation Proofpoint tracks UNK_DeadDrop separately due to its email-led delivery, large-scale repository creation, and self-contained payloads that persist even after infrastructure takedowns. Though attribution remains unconfirmed, the campaign aligns with North Korea’s history of targeting developers since 2022.
INCIDENT DETAILS -
TYPE
Phishing, Malware, Credential Theft, Cryptocurrency Theft
MOTIVATION
Financial gain (cryptocurrency theft), credential theft
IMPACT
Financial Loss: Cryptocurrency wallet drainageData Compromised: Browser credentials, cryptocurrency wallet data, saved passwords, cookiesSystems Affected: macOS, Linux, Windows systems running VS Code or CursorIdentity Theft Risk: High (PII and credentials stolen)Payment Information Risk: High (cryptocurrency wallets targeted)
DATA BREACH
Browser credentialsCryptocurrency wallet dataSaved passwordsCookiesSensitivity Of Data: High (PII, financial data)Personally Identifiable Information: Browser credentials, saved passwords
MARCH 2026
767Before Incident
FEBRUARY 2026
771Before Incident
Vulnerability
11 Feb 2026 • GitLab
GitLab: GitLab Patches Multiple Vulnerabilities Enabling DoS and Cross-Site Scripting Attacks

GitLab Releases Critical Security Patches for High-Severity Vulnerabilities

773After Incident
CRITICAL-2
GIT1770804634
GitLab Releases Critical Security Patches for High-Severity Vulnerabilities GitLab has issued urgent security updates for its Community Edition (CE) and Enterprise Edition (EE), addressing multiple high-severity vulnerabilities in versions 18.8.4, 18.7.4, and 18.6.6. The patches mitigate risks including denial-of-service (DoS) attacks, cross-site scripting (XSS), and unauthorized data access, which could expose sensitive information like access tokens. The most critical flaw, CVE-2025-7659 (CVSS 8.0), involves incomplete validation in GitLab’s Web IDE, allowing unauthenticated attackers to steal tokens and access private repositories. Other notable vulnerabilities include CVE-2025-8099 (CVSS 7.5), a DoS risk in GraphQL introspection, and CVE-2026-0958 (CVSS 7.5), which exploits weak JSON validation to exhaust server resources. XSS and injection flaws, such as CVE-2025-14560 (CVSS 7.3), could enable session hijacking or fake content delivery. Additional risks include DoS in Markdown tools and dashboards, as well as server-side request forgery (SSRF) vulnerabilities that could probe internal networks. GitLab.com users are already protected, but self-managed instances require immediate updates to prevent exploitation. The patches highlight the ongoing threat of automated attacks targeting unpatched systems. Full details are available in GitLab’s release notes.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationData Exposure
IMPACT
Access tokensPrivate repository dataSensitive informationGitLab Community Edition (CE)GitLab Enterprise Edition (EE)Potential unauthorized access to private repositoriesServer resource exhaustion
DATA BREACH
Access tokensPrivate repository dataSensitivity Of Data: High
FEBRUARY 2026
775Before Incident
Vulnerability
03 Feb 2026 • GitLab
GitLab: CISA Warns of Actively Exploited GitLab SSRF Vulnerability in Community and Enterprise Editions

Actively Exploited SSRF Vulnerability in GitLab (CVE-2021-39935)

771After Incident
CRITICAL-4
GIT1770208485
CISA Warns of Actively Exploited SSRF Vulnerability in GitLab The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding an actively exploited Server-Side Request Forgery (SSRF) vulnerability in GitLab Community and Enterprise Editions, tracked as CVE-2021-39935. The flaw, added to CISA’s Known Exploited Vulnerabilities Catalog on February 3, 2026, allows unauthenticated attackers to force GitLab servers to make unauthorized requests via the CI Lint API, potentially exposing internal systems or enabling further exploitation. The vulnerability stems from improper URL validation during CI/CD configuration checks, enabling attackers to scan internal networks, leak credentials, or exploit connected services. While GitLab patched the issue in 2021, recent reports indicate renewed exploitation of unpatched instances, particularly those exposed to the internet. CISA has set a February 24, 2026 deadline for federal agencies to mitigate the flaw under Binding Operational Directive (BOD) 22-01. The agency highlights the risk of supply-chain attacks, as SSRF flaws in CI/CD pipelines can expose cloud metadata services, revealing sensitive tokens or configurations. Though no specific threat actor has been attributed, SSRF vulnerabilities have historically been used for crypto-mining, lateral movement, and initial access in broader compromises. GitLab has released security updates for affected versions. Organizations are advised to upgrade immediately, restrict API exposure, monitor logs for suspicious activity, and implement network segmentation to limit potential damage. Given GitLab’s widespread use in DevOps workflows, unpatched instances remain a prime target for attackers.
INCIDENT DETAILS -
TYPE
Server-Side Request Forgery (SSRF)
MOTIVATION
crypto-mininglateral movementinitial access
IMPACT
Data Compromised: credentials, sensitive tokens, configurationsSystems Affected: GitLab Community and Enterprise EditionsOperational Impact: supply-chain attacks, exposure of cloud metadata services
DATA BREACH
credentialssensitive tokensconfigurationsSensitivity Of Data: high
JANUARY 2026
775Before Incident
DECEMBER 2025
775Before Incident
NOVEMBER 2025
774Before Incident
JUNE 2025
777Before Incident
Vulnerability
16 Jun 2025 • GitLab
GitLab

GitLab Critical Security Patches Addressing Multiple Vulnerabilities Including Prompt-Injection Flaw in GitLab Duo

772After Incident
CRITICAL-5
GIT5234552111325
GitLab disclosed nine vulnerabilities across its Community (CE) and Enterprise (EE) editions, with CVE-2025-6945 being the most critical—a prompt-injection flaw in GitLab Duo’s AI-powered review feature that allows authenticated attackers to exfiltrate sensitive data from confidential issues via hidden prompts in merge request comments. This exploit leverages AI’s lack of input validation, turning an AI assistant into a vector for data leakage. Additionally, CVE-2025-11224 (a stored XSS vulnerability in the Kubernetes proxy) enables authenticated users to execute malicious scripts, while CVE-2025-2615 and CVE-2025-7000 expose confidential data through GraphQL subscriptions and branch name leaks, respectively. The flaws span versions back to 15.10, creating a broad attack surface for organizations running unpatched instances. Though no evidence of active exploitation exists, the vulnerabilities risk unauthorized access to proprietary code, internal discussions, and project metadata, potentially aiding supply-chain attacks or competitive espionage. GitLab has released patches (versions 18.5.2, 18.4.4, 18.3.6) and urged immediate upgrades for self-managed deployments.
INCIDENT DETAILS -
TYPE
Vulnerability DisclosurePatch Release
IMPACT
Sensitive information from confidential issues (CVE-2025-6945)Confidential branch names (CVE-2025-7000)Restricted branch names (CVE-2025-6171)Confidential information via GraphQL (CVE-2025-2615)GitLab Community Edition (CE)GitLab Enterprise Edition (EE)GitLab Duo (AI-powered review feature)Kubernetes proxy functionalityGraphQL subscriptionsPackages APIGitLab PagesMarkdown processingPotential unauthorized access to sensitive dataRisk of stored XSS attacks in Kubernetes proxyExposure of confidential issues via AI feature exploitationPotential reputational damage due to AI-powered feature vulnerabilitiesTrust erosion in access control mechanisms
DATA BREACH
Confidential issue detailsConfidential branch namesRestricted branch namesSensitive information accessible via GraphQL subscriptionsSensitivity Of Data: High (includes confidential project information and access-controlled data)Potential exfiltration via prompt injection (CVE-2025-6945)Unauthorized access to confidential data via multiple vectors
MARCH 2022
759Before Incident
Vulnerability
01 Mar 2022 • GitLab
GitLab

Critical Vulnerability in GitLab Community

755After Incident
CRITICAL-4
GIT1372322
A critical vulnerability discovered in GitLab Community could enable an attacker to steal runner registration tokens. The vulnerability announced in GitLab security advisory affects all versions. If this vulnerability is exploited then an unauthorized user can steal runner registration tokens through an information disclosure vulnerability using quick actions commands.
INCIDENT DETAILS -
TYPE
Information Disclosure
IMPACT
Data Compromised: Runner Registration Tokens
DATA BREACH
Type Of Data Compromised: Runner Registration Tokens
JANUARY 2022
783Before Incident
Cyber Attack
01 Jan 2022 • GitLab
GitLab: North Korean fake IT worker tradecraft exposed

North Korean Threat Actors Exploit IT Recruitment to Deploy Malware and Infiltrate Organizations

758After Incident
CRITICAL-25
GIT1773311240
North Korean Threat Actors Exploit IT Recruitment to Deploy Malware and Infiltrate Organizations GitLab’s recent research has uncovered a sophisticated campaign by North Korean threat actors who weaponize the tech recruitment process to target software developers particularly in the cryptocurrency and financial sectors. Posing as recruiters or hiring managers, these actors trick developers into executing malicious payloads under the guise of technical assessments, bypassing traditional security defenses by exploiting trusted hiring pipelines. The operation, active since at least 2019 and intensifying in 2022, involves fake IT workers often operating from locations like Moscow and Beijing who infiltrate organizations through freelance platforms and smaller companies. One Beijing-based cell, comprising eight North Korean nationals, generated over $1.64 million between Q1 2022 and Q3 2025, with individual earnings exceeding $11,000 per member in Q3 2025. These groups maintain elaborate synthetic personas, sometimes controlling up to 21 unique identities, complete with stolen U.S. documents and fabricated professional histories. Key Tactics and Evolution - Malware Delivery: Threat actors abuse private code repositories (including GitLab and Visual Studio Code) to distribute obfuscated loaders for malware like BeaverTail and Ottercookie, often hosted externally. - AI-Driven Tradecraft: North Korean groups increasingly rely on AI to refine malware obfuscation, automate synthetic identity creation, and scale deception operations. Tools like ClickFix and generative AI have lowered the barrier for large-scale fraud. - Targeting Preferences: While U.S.-based developers and fintech firms are primary targets, the campaigns are opportunistic, spanning multiple industries. Smaller organizations with limited vetting processes are particularly vulnerable. - Operational Security: Actors use consumer VPNs, VPS infrastructures, and laptop farms to mask their origins, though some access was traced to dedicated servers. GitLab’s Response and Findings GitLab disrupted the campaign by banning 131 North Korean-attributed accounts in 2025, many linked to the "Contagious Interview" scheme. Compromised repositories contained sensitive data, including passport scans, banking records, performance reviews, and financial spreadsheets revealing the groups’ internal hierarchies and revenue streams. Performance evaluations even assessed members’ contributions to household tasks (e.g., laundry, shared groceries) alongside technical and ideological adherence. Broader Implications The research highlights the parallel operations of multiple DPRK teams, which share tradecraft but operate with limited coordination. The shift toward AI-enhanced deception and malicious NPM dependencies signals a growing sophistication in social engineering and supply-chain attacks. While freelance platforms remain a common entry point, larger organizations are also at risk as these scams expand in scope. GitLab’s report includes over 600 indicators of compromise to aid defenders in detecting and mitigating such threats. The findings underscore the persistent threat posed by state-aligned actors exploiting trust in the tech hiring ecosystem.
INCIDENT DETAILS -
TYPE
Malware DeploymentSocial EngineeringSupply-Chain Attack
MOTIVATION
Financial GainEspionageData Exfiltration
IMPACT
Financial Loss: $1.64 million (Q1 2022 - Q3 2025)Passport scansBanking recordsPerformance reviewsFinancial spreadsheetsPrivate code repositoriesDeveloper workstationsOperational Impact: Infiltration of organizations via freelance platforms and smaller companiesIdentity Theft Risk: High (stolen U.S. documents used for synthetic identities)
DATA BREACH
Personally Identifiable InformationFinancial DataInternal DocumentsSensitivity Of Data: High (passport scans, banking records, performance reviews)Data Exfiltration: YesSpreadsheetsScanned DocumentsPersonally Identifiable Information: Yes (stolen U.S. documents, passport scans)
JANUARY 2021
782Before Incident
Vulnerability
01 Jan 2021 • GitLab
GitLab and Federal Civilian Executive Branch: CISA Warns of Exploited GitLab Community and Enterprise SSRF Vulnerability

Critical GitLab SSRF Vulnerability Under Active Exploitation, CISA Warns

781After Incident
CRITICAL-1
GITGAL1770201332
Critical GitLab SSRF Vulnerability Under Active Exploitation, CISA Warns The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2021-39935, a severe server-side request forgery (SSRF) vulnerability in GitLab Community and Enterprise Editions, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild. The flaw resides in GitLab’s CI Lint API, allowing unauthenticated attackers to manipulate the server into making unauthorized requests to internal systems. By exploiting this weakness, threat actors can bypass perimeter defenses, access restricted resources, and potentially move laterally within compromised networks. The vulnerability (tracked as CWE-918) poses risks including data exposure, supply chain compromise via CI/CD pipeline manipulation, and unauthorized access to cloud metadata or internal infrastructure. Both GitLab Community and Enterprise Editions are affected, with CISA’s inclusion in the KEV catalog underscoring the urgency of remediation. While no direct links to ransomware campaigns have been confirmed, the flaw’s potential for initial access makes it a prime target for advanced persistent threat (APT) groups and initial access brokers. Under Binding Operational Directive 22-01, Federal Civilian Executive Branch (FCEB) agencies must patch or mitigate the vulnerability by February 24, 2026. Organizations unable to apply fixes are advised to discontinue use of affected GitLab instances until updates are available. GitLab has released patches, and administrators are urged to upgrade immediately, review CI Lint API configurations, and monitor logs for suspicious activity such as unusual API requests or unexpected internal connections originating from GitLab servers. Cloud-hosted GitLab users should adhere to BOD 22-01 guidance for securing cloud services. The incident highlights the growing threat of SSRF attacks, which can evade traditional security measures by leveraging trusted servers as proxies for malicious activity.
INCIDENT DETAILS -
TYPE
Server-Side Request Forgery (SSRF)
MOTIVATION
Data exposureSupply chain compromiseUnauthorized access to internal systems
IMPACT
Data Compromised: Potential data exposureSystems Affected: GitLab Community and Enterprise EditionsOperational Impact: Potential lateral movement within networks, supply chain compromise via CI/CD pipeline manipulation

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for GitLab ?
?
What was GitLab's A.I Rankiteo Cyber Score in September 2026 ?
?
What was GitLab's A.I Rankiteo Cyber Score in August 2026 ?
?
What was GitLab's A.I Rankiteo Cyber Score in July 2026 ?
?
What was GitLab's A.I Rankiteo Cyber Score in June 2026 ?
?
What was GitLab's A.I Rankiteo Cyber Score in May 2026 ?
?
What was GitLab's A.I Rankiteo Cyber Score in April 2026 ?
?
What was GitLab's A.I Rankiteo Cyber Score in March 2026 ?
?
What was GitLab's A.I Rankiteo Cyber Score in February 2026 ?
?
What was GitLab's A.I Rankiteo Cyber Score in January 2026 ?
?
What was GitLab's A.I Rankiteo Cyber Score in December 2025 ?
?
What was GitLab's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on GitLab's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with GitLab ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view GitLab's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?