Ethical Hacking News
GitLab Users Urged to Patch After Research Reveals Critical RCE Chain: A critical vulnerability has been discovered in GitLab that could allow attackers to execute commands on the server. The vulnerability, which affects authenticated users on unpatched versions of GitLab CE and EE, highlights the importance of keeping software up-to-date and emphasizes the need for vigilance in the security community.
GitLab users are urged to patch immediately due to a critical RCE chain found in the platform. A remote code execution vulnerability was discovered, allowing attackers to access sensitive data. The vulnerability affects authenticated users on unpatched versions of GitLab CE and EE, including releases from 15.2.0 through 18.9. No admin rights or interaction are needed to exploit the vulnerability, making it particularly concerning. Users are advised to update their software as soon as possible to mitigate the risk of exploitation.
GitLab Users Urged to Patch After Research Reveals Critical RCE Chain
A recent vulnerability discovery has highlighted the critical need for GitLab users to update their software immediately, as a remote code execution (RCE) chain has been found in the popular source code management platform. According to research published by Depthfirst, a group of security experts discovered that two vulnerabilities in the Oj parser, a low-level dependency used by GitLab, could be chained together to execute commands on the server.
The first vulnerability is an unchecked nesting stack overflow, which allows an attacker to control how far the sweep goes into adjacent parser fields. The second vulnerability provides the address needed to execute the command. By chaining these two vulnerabilities, attackers can gain remote code execution inside a GitLab Puma worker, potentially allowing them to access sensitive data, such as source code, Rails secrets, and service credentials.
The research team found that this vulnerability affects authenticated users on unpatched versions of GitLab CE and EE, which includes releases from 15.2.0 through 18.9. The researchers emphasized that no admin rights, no CI access, and no victim interaction are needed to exploit the vulnerability, making it particularly concerning.
To further highlight the severity of this issue, Depthfirst reported that two memory-safety bugs had survived in Oj's parser for nearly five years before being discovered. These vulnerabilities were introduced in August 2021 and remained there until June 10, 2026, when GitLab patched them.
GitLab CE and EE versions 15.2.0 through 18.10.7, 18.11.0 through 18.11.4, and 19.0.0 through 19.0.1 are affected across all tiers. Releases before 15.2 used a different JSON parser in this path and aren't vulnerable.
In light of these findings, the security community is urging users to update their software as soon as possible to mitigate the risk of exploitation. However, researchers pointed out that no configuration-only workaround has been validated by Depthfirst or GitLab, making patching a necessity.
The discovery of this critical vulnerability serves as a reminder of the importance of keeping software up-to-date and the ongoing need for vigilance in the security community. As cybersecurity threats continue to evolve, it's essential for users to stay informed about potential vulnerabilities and take proactive steps to protect themselves.
Related Information:
https://www.ethicalhackingnews.com/articles/Critical-GitLab-Vulnerability-Exposed-A-Detailed-Analysis-ehn.shtml
https://securityaffairs.com/196062/hacking/gitlab-users-urged-to-patch-after-research-reveals-critical-rce-chain.html
Published: Mon Jul 27 08:11:04 2026 by llama3.2 3B Q4_K_M