View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

GitLab Memory-Safety Flaws in Oj JSON Parser Enable Remote Code

🕵️ RESEARCH & DEEP DIVES

  • GitLab Memory-Safety Flaws in Oj JSON Parser Enable Remote Code Execution Two memory-safety bugs in GitLab's Oj JSON parser allow remote code execution by authenticated users.

    • Applies to self-managed GitLab CE/EE versions 15.2.0–18.10.7, 18.11.0–18.11.4, and 19.0.0–19.0.1
    • Vulnerabilities are two long-standing memory-safety flaws in the Ruby Oj JSON parser used by GitLab
    • Attack exploits crafted Jupyter Notebook (.ipynb) files pushed by any authenticated user with push and diff-view rights
    • Chained flaws enable heap pointer leak and callback pointer overwrite, defeating ASLR and executing code as 'git' user
    • Exploitation risks exposure of source code, Rails secrets, internal services, and allows lateral movement 📎 Coverage: cybersecuritynews.com · 👁 via Cyber Security News
  • Security Flaw in Vatican’s Click to Pray App Exposes Data of 700,000+ Users The Vatican’s Click to Pray app has leaked user data for over six months.

    • Applies to over 700,000 global users of the Vatican’s Click to Pray mobile app
    • User data was exposed due to a security flaw in the app
    • Data leak persisted for more than six months without being fixed
    • Details on attack vector or exploited vulnerability have not been disclosed 📎 Coverage: tomshardware.com · 👁 via r/cybersecurity
  • Researcher Claims Universal Jailbreak for Leading AI Models Including GPT-5.6 A researcher claims to have developed a universal jailbreak effective on all major AI models.

    • Applies to top large language models: GPT-5.6 Sol, Claude Opus 5, and Fable
    • The jailbreak bypasses safety filters to produce disallowed or high-risk outputs
    • Claimed universal method works across all tested models and categories
    • Researcher withholding full technique for responsible disclosure amid regulatory concerns
    • Highlights gaps in safety training, guardrail robustness, and cross-model attack generalization 📎 Coverage: cybersecuritynews.com · 👁 via Cyber Security News

📋 ADVISORIES

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check