Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

GitLab

20 articles

SC Media general GitLab 6d ago

GitLab warns of critical AI Gateway vulnerability allowing command execution

A critical vulnerability in GitLab's AI Gateway that could allow attackers to execute arbitrary commands on affected instances.

SC Media → Details

Security Affairs general GitLab Oct 3

CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed

GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways. GitLab has...

1 IOC

Security Affairs → Details

GBHackers general GitLab Oct 3

Critical GitLab AI Gateway Flaw Lets Attackers Execute Arbitrary Commands

GitLab has issued emergency security updates for a critical vulnerability in its Self-Hosted AI Gateway that could allow authenticated attackers to execute a...

1 IOC

GBHackers → Details

The Hacker News general GitLab Oct 2

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab...

The Hacker News → Details

BleepingComputer general GitLab Oct 2

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instance...

BleepingComputer → Details

CSO Online enterprise GitLab Sep 25

GitLab issue email’s only security is obscurity

It was meant to make life simpler: a secret email address to which developers can send a message and create an issue in their GitLab project. But poor securi...

T1598

CSO Online → Details

SC Media general GitLab Sep 24

Private GitLab email addresses exposed in public documentation

These email addresses, part of GitLab's "Email work item to this project" feature, contain long-lived tokens that act as credentials.

SC Media → Details

BleepingComputer general GitLab Sep 24

Exposed GitLab project email addresses let attackers push code

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and...

BleepingComputer → Details

GBHackers general GitLab Sep 24

GitLab Email Token Lets Attackers Push Code to Main and Execute CI/CD Jobs

A long-lived GitLab incoming email token embedded in project email addresses for the “Email work item” feature can be exploited to push attacker-controlled c...

GBHackers → Details

The Hacker News general GitLab Sep 23

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name,...

The Hacker News → Details

CSO Online enterprise GitLab Sep 15

A maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove

Yet another security vulnerability has been discovered in GitLab infrastructure, this one a perfect 10 in severity. CVE-2026-85706, the second flaw GitLab ha...

1 IOC

CSO Online → Details

Rapid7 Blog vendor GitLab Sep 14

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresse...

1 IOC

Rapid7 Blog → Details

Infosecurity Magazine general GitLab Sep 14

Hackers Exploit Maximum Severity Flaw in GitLab

CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.

Infosecurity Magazine → Details

BleepingComputer general GitLab Sep 14

CISA: Hackers now exploit max severity GitLab flaw in attacks

The U.S.

BleepingComputer → Details

Security Affairs general GitLab Sep 13

GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours

CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure.

1 IOC

Security Affairs → Details

GBHackers general GitLab Sep 12

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S.

1 IOC

GBHackers → Details

SC Media general GitLab Sep 11

Max severity GitLab path traversal flaw under active reconnaissance

The flaw could enable sensitive files to be read with just an HTTP request.

T1592

SC Media → Details

Cyberscoop general GitLab Sep 11

GitLab’s critical flaw is already drawing internet-wide probes

One flaw allows an unauthenticated attacker to read files from the server. GitLab urged operators of self-managed installations to upgrade immediately.

Cyberscoop → Details

SecurityWeek general GitLab Sep 11

GitLab Vulnerability Exploited One Day After Disclosure

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Expl...

SecurityWeek → Details

CISA Advisories advisories GitLab Sep 11

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85706 GitLab Co...

1 IOC

CISA Advisories → Details

1 2 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA