Threat hunts for GitLab
3 hunts covering GitLab, each with a hypothesis, the queries that test it and what the hunt cannot see.
3 hunts
-
highResearch by Rapid7
GitLab Critical API Exploitation
An adversary is exploiting unauthenticated path traversal in the GitLab repository commits API to read server configuration or using insecure deserialization in Duo Chat to extract sensitive credentials.
3 query2 analytic2 checkpoint1 action2 taskCVE-2026-85706 · CVE-2026-87719 -
high Part 2 of 2Research by Rapid7
Internal Coercion and Editor Persistence
An adversary is using rogue DHCPv6 services to perform DNS takeover for Kerberos relaying, or has established persistence via unauthorized Kate editor plugins on compromised hosts.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-18729 · CVE-2026-20929 -
high Part 1 of 2Research by Rapid7
Exploitation of Web-Facing GitLab and Langflow
An adversary is exploiting GitLab unauthenticated file reads or Langflow authenticated RCE to access repository secrets or execute code on the server host, starting from public-facing assets.
3 query1 analytic1 checkpoint1 action2 taskCVE-2026-18729 · CVE-2026-20929