Depthfirst
GitLab Vulnerabilities Enable Remote Code Execution via Oj Parser Flaws
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical security vulnerability in GitLab has been disclosed, stemming from two long-standing memory-safety flaws in the Oj JSON parsing library. Discovered by Depthfirst's automated analysis, these flaws allow authenticated users to execute remote code on default GitLab installations. The vulnerabilities, identified as CVE-2026-54901 and CVE-2026-54903, have been present for nearly five years and affect all GitLab tiers. The attack vector involves a crafted Jupyter notebook that exploits Oj's C parser within a Puma worker. GitLab has released patches in versions 18.10.8, 18.11.5, and 19.0.2, which bundle the fixed Oj version 3.17.3. Users are urged to upgrade their self-managed GitLab installations to mitigate the risk. The flaws expose sensitive information, including source code and Rails secrets, making the situation critical for affected users.
Key Points: • Two memory-safety vulnerabilities in Oj allow remote code execution on GitLab. • All GitLab tiers are affected, including CE and EE versions. • Patches are available in GitLab versions 18.10.8, 18.11.5, and 19.0.2.