Huntbase Hub · All hunts

Threat hunts for GitLab

3 hunts covering GitLab, each with a hypothesis, the queries that test it and what the hunt cannot see.

3 hunts

  1. high
    Research by Rapid7

    GitLab Critical API Exploitation

    An adversary is exploiting unauthenticated path traversal in the GitLab repository commits API to read server configuration or using insecure deserialization in Duo Chat to extract sensitive credentials.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-85706 · CVE-2026-87719
  2. high Part 2 of 2
    Research by Rapid7

    Internal Coercion and Editor Persistence

    An adversary is using rogue DHCPv6 services to perform DNS takeover for Kerberos relaying, or has established persistence via unauthorized Kate editor plugins on compromised hosts.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-18729 · CVE-2026-20929
  3. high Part 1 of 2
    Research by Rapid7

    Exploitation of Web-Facing GitLab and Langflow

    An adversary is exploiting GitLab unauthenticated file reads or Langflow authenticated RCE to access repository secrets or execute code on the server host, starting from public-facing assets.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-18729 · CVE-2026-20929