GitLab Vulnerabilities Enable Remote Code Execution via Oj Parser Flaws

GitLab Vulnerabilities Enable Remote Code Execution via Oj Parser Flaws

First seen 26 Jul 2026, 11:03 UTC DepthfirstCybersecuritynews 81% similarity 72.6

Article Content

Browse articles
ThreatCluster

A critical security vulnerability in GitLab has been disclosed, stemming from two long-standing memory-safety flaws in the Oj JSON parsing library. Discovered by Depthfirst's automated analysis, these flaws allow authenticated users to execute remote code on default GitLab installations. The vulnerabilities, identified as CVE-2026-54901 and CVE-2026-54903, have been present for nearly five years and affect all GitLab tiers. The attack vector involves a crafted Jupyter notebook that exploits Oj's C parser within a Puma worker. GitLab has released patches in versions 18.10.8, 18.11.5, and 19.0.2, which bundle the fixed Oj version 3.17.3. Users are urged to upgrade their self-managed GitLab installations to mitigate the risk. The flaws expose sensitive information, including source code and Rails secrets, making the situation critical for affected users.

Key Points: • Two memory-safety vulnerabilities in Oj allow remote code execution on GitLab. • All GitLab tiers are affected, including CE and EE versions. • Patches are available in GitLab versions 18.10.8, 18.11.5, and 19.0.2.

ThreatCluster AI

Timeline

2026-06-30
CVE-2026-54901 published
Memory-safety vulnerability in Oj JSON parser disclosed, affecting GitLab installations.
Depthfirst
2026-06-30
CVE-2026-54903 published
Second memory-safety vulnerability in Oj JSON parser disclosed, enabling remote code execution.
Depthfirst
2026-06-30
CVE-2026-54897 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-30
CVE-2026-54900 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-30
CVE-2026-54902 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-30
CVE-2026-54898 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-30
CVE-2026-54502 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-30
CVE-2026-54899 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-30
CVE-2026-54896 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-25
First public PoC released
Proof of concept for exploiting Oj vulnerabilities published, demonstrating remote code execution.
Cybersecuritynews

Community

Browse all →