{
  "id": 11583945,
  "title": "918,415 GitLab Assets on HTTP: Measuring the Source of Truth",
  "url": "https://urgent.news/2026/10/03/918-415-gitlab-assets-on-http-measuring-the-source-of-truth",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-03T02:40:24.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/onaeiuspkz/918415-gitlab-assets-on-http-measuring-the-source-of-truth-272m"
  },
  "original_language": "en",
  "account": "GitLab assets discovered on HTTP: assessing the source of truth\n\nGitLab assets found on HTTP make up around 69 percent of the total fingerprinted assets, according to measurements conducted by ZoomEye on October 1, 2026. The HTTP-scoped figure represents 918,415 assets out of the total.\n\nHowever, this measurement is not a comprehensive assessment of all GitLab instances. It only covers reachable assets and does not provide information about whether an instance is self-managed or hosted by a vendor, the registration status, or the patched version being used.\n\nVendor research has identified a GitLab vulnerability (CVE-2026-85706) with observed exploitation attempts, advising customers to upgrade promptly. Nevertheless, the advisory does not include a mechanism for determining which instances have been successfully compromised.\n\nIt is important to note that a significant portion of the fingerprinted population is hosted by the vendor or managed platforms that centrally apply updates. These instances are outside the customer's responsibility to patch, even though they are included in the global service count.\n\nTo make this measurement actionable, three refinements are necessary:\n1. Scope by organization: Combine app= GitLab && service= http with organizational or network conditions to produce a list of owned instances rather than a global figure.\n2. Separate the web interface from the SSH endpoint used for Git operations, as both have different exposure requirements.\n3. Check for open registration and public project visibility, as these features can turn a reachable instance into an intelligence source for an attacker.\n\nGitLab's own security posture is not the focus of this article; the measurement is. The ZoomEye records for these hosts include HTTP headers, certificate details, and response characteristics, which can help operators distinguish between self-managed deployments and hosted instances and confirm the interface that is answering.\n\nWhile the count of 918,415 HTTP-scoped GitLab assets provides context, it is essential to identify the specific finding that should not be on the list. This information can help organizations prioritize their patching efforts and secure their GitLab deployments effectively.",
  "summary": "918,415 GitLab Assets on HTTP: Measuring the Source of Truth Source control is measured like any other web service, and it should be interpreted differently, because the system that stores the code also stores the credentials that build and deploy it. The measurement ZoomEye queries executed on 1 October 2026 at 02:33 UTC, global scope and all asset types: | Query | Matching assets | | --- | ---:…",
  "key_points": [
    "69% of GitLab assets discovered on HTTP, according to ZoomEye measurement on October 1, 2026",
    "918,415 HTTP-scoped assets out of total fingerprinted GitLab assets",
    "Advisory advises prompt upgrade for identified GitLab vulnerability (CVE-2026-85706)"
  ],
  "editors_take": "The measurement of 918,415 GitLab assets on HTTP highlights the need for organizations to refine their approach to identifying and securing their own instances, particularly in light of a known vulnerability.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}