Urgent.News

What's breaking now, across thousands of outlets.

Tech

918,415 GitLab Assets on HTTP: Measuring the Source of Truth

918,415 GitLab Assets on HTTP: Measuring the Source of Truth Source control is measured like any other web service, and it should be interpreted differently, because the system that stores the code also stores the credentials that build and deploy it. The measurement ZoomEye queries executed on 1 October 2026 at 02:33 UTC, global scope and all asset types: | Query | Matching assets | | --- | ---:…

GitLab assets discovered on HTTP: assessing the source of truth

GitLab assets found on HTTP make up around 69 percent of the total fingerprinted assets, according to measurements conducted by ZoomEye on October 1, 2026. The HTTP-scoped figure represents 918,415 assets out of the total.

However, this measurement is not a comprehensive assessment of all GitLab instances. It only covers reachable assets and does not provide information about whether an instance is self-managed or hosted by a vendor, the registration status, or the patched version being used.

Vendor research has identified a GitLab vulnerability (CVE-2026-85706) with observed exploitation attempts, advising customers to upgrade promptly. Nevertheless, the advisory does not include a mechanism for determining which instances have been successfully compromised.

It is important to note that a significant portion of the fingerprinted population is hosted by the vendor or managed platforms that centrally apply updates. These instances are outside the customer's responsibility to patch, even though they are included in the global service count.

To make this measurement actionable, three refinements are necessary:

1. Scope by organization: Combine app= GitLab && service= http with organizational or network conditions to produce a list of owned instances rather than a global figure.

2. Separate the web interface from the SSH endpoint used for Git operations, as both have different exposure requirements.

3. Check for open registration and public project visibility, as these features can turn a reachable instance into an intelligence source for an attacker.

GitLab's own security posture is not the focus of this article; the measurement is. The ZoomEye records for these hosts include HTTP headers, certificate details, and response characteristics, which can help operators distinguish between self-managed deployments and hosted instances and confirm the interface that is answering.

While the count of 918,415 HTTP-scoped GitLab assets provides context, it is essential to identify the specific finding that should not be on the list. This information can help organizations prioritize their patching efforts and secure their GitLab deployments effectively.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

14. Union-Find (DSU) + Minimum Spanning Trees

This is the natural next topic after graphs and shortest paths. 1. Union-Find / Disjoint Set Union (DSU) Union-Find is used when you need to repeatedly answer: “Are these two nodes in the same…

  • Union-Find data structure determines node groups
  • Core operations: find(x), union(a, b)
  • Path compression optimizes find() operations

Preserve plus signs and ampersands in demo search URLs

Build search parameters from raw values with URLSearchParams so a plus sign or ampersand in the user's input survives the round trip.

  • Preserve plus signs and ampersands in user input
  • Use URL object and URLSearchParams interface
  • Test with various special character inputs

gVisor is being donated to CNCF

  • Google donates gVisor project to CNCF, Apache 2.0 licensed
  • gVisor provides security without virtualization checkbox
  • CNCF aims to enhance gVisor adoption beyond tech companies

What OMA returns when its test gate fails

oh-my-agent (OMA) can rerun a configured test script when an active workflow tries to stop. This example exercises that behavior with manual hook calls and a deliberately broken expiry check.

  • OMA returns decision block when test gate fails
  • Failure reason: stop gate test failed
  • Issue resolved by fixing code comparison

More from Saturday 3 October →