German authorities issued multiple security advisories for GitLab and Gitea, warning of newly tracked vulnerabilities that affect widely used source code management and DevOps platforms. Two separate dCERT notices flagged multiple vulnerabilities in GitLab, indicating more than one security issue requiring administrator attention across the platform.
A separate dCERT advisory warned that Gitea contains a vulnerability that can bypass security measures, raising concern that protections intended to restrict access or enforce policy may be circumvented. While the advisories did not publish technical synopses in the referenced notices, the alerts indicate that organizations using GitLab or Gitea should review vendor guidance, identify affected deployments, and prioritize patching or other mitigations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
dCERT issued advisory 2026-1221 concerning multiple vulnerabilities in GitLab. The reference content does not specify whether this is a new set of flaws or an update to earlier reporting.
dCERT issued advisory 2026-1216 for a Gitea vulnerability that allows bypassing security measures. The reference does not include additional technical or impact details.
dCERT issued advisory 2026-0833 concerning multiple vulnerabilities affecting GitLab. No further technical details are provided in the reference content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
dcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.