securityaffairs.com 7/27/2026, 11:51:26 AM · external

GitLab patches RCE flaw in Oj JSON parser after five year wait

GitLab patches RCE flaw in Oj JSON parser after five year wait
CyberSIXT Evidence Panel
Primary Source depthfirst.com

RESEARCH from Depthfirst highlights a critical remote code execution (RCE) vulnerability in GitLab, resulting from two memory corruption bugs in the Oj JSON parser. These vulnerabilities affect authenticated users who can push to projects and view commit diffs. The flaws, which remain unpatched for over five years, are exploited all the way through GitLab’s notebook diff renderer. GitLab has acknowledged the issue and released patches, advising users of versions 15.2.0 through 19.0.1 to upgrade accordingly. The exploit can lead to severe consequences, including source-code disclosure and credential theft.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline