Depthfirst GitLab Vulnerabilities Enable Remote Code Execution via Oj Parser Flaws
Article Content
- •Two memory-safety vulnerabilities in Oj allow remote code execution on GitLab.
- •All GitLab tiers are affected, including CE and EE versions.
- •Patches are available in GitLab versions 18.10.8, 18.11.5, and 19.0.2.
A critical security vulnerability in GitLab has been disclosed, stemming from two long-standing memory-safety flaws in the Oj JSON parsing library. Discovered by Depthfirst's automated analysis, these flaws allow authenticated users to execute remote code on default GitLab installations. The vulnerabilities, identified as CVE-2026-54901 and CVE-2026-54903, have been present for nearly five years and affect all GitLab tiers. The attack vector involves a crafted Jupyter notebook that exploits Oj's C parser within a Puma worker. GitLab has released patches in versions 18.10.8, 18.11.5, and 19.0.2, which bundle the fixed Oj version 3.17.3. Users are urged to upgrade their self-managed GitLab installations to mitigate the risk. The flaws expose sensitive information, including source code and Rails secrets, making the situation critical for affected users.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-54502 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…