Summary
GitLab has patched a vulnerability that allowed unauthenticated attackers to enumerate the email addresses of members of any public GitLab project. The flaw existed in GitLab’s project membership API, which returned contributor email addresses in responses to unauthenticated requests against public projects. An attacker could harvest the email addresses of all members of a target project — including repository maintainers and CI/CD pipeline administrators — and use those addresses for targeted phishing campaigns designed to steal repository access credentials or push access tokens. Successful follow-on attacks could allow unauthorized code commits, injection of malicious code into CI/CD pipelines, and access to secrets stored in pipeline environment variables. GitLab has released patches in versions 17.4.1, 17.3.4, and 17.2.8.
Timeline
| Date | Event |
|---|---|
| September 2026 | GitLab vulnerability discovered; project member email addresses exposed via unauthenticated API requests against public projects |
| Sep 23, 2026 | GitLab releases patches in versions 17.4.1, 17.3.4, and 17.2.8; BleepingComputer reports exploitation activity |
What Happened
The vulnerability affected GitLab’s project membership API endpoint, which is intended to return public contributor information for public projects. The API incorrectly included email addresses — which GitLab treats as private user data even for public project contributors — in its unauthenticated response payload. Any attacker who could identify a public GitLab project could query the membership API and retrieve a complete list of contributor email addresses without authentication.
The practical attack path is supply chain-focused: an attacker identifies a widely used open-source project hosted on GitLab, enumerates the email addresses of its maintainers and key contributors, and launches targeted credential phishing campaigns against those specific individuals. A maintainer who surrenders their GitLab credentials or a personal access token gives the attacker the ability to push commits directly to the project repository, modify CI/CD pipeline definitions, inject malicious code into build artifacts, or steal secrets from pipeline environment variables. For projects with many downstream consumers, a single successful maintainer compromise can propagate malicious code into hundreds or thousands of dependent projects through normal package update mechanisms. Self-managed GitLab instances should update to patched versions immediately. GitLab.com has already been patched by GitLab.
Domain Intelligence
gitlab.com — 73.06
gitlab.com scores at 73.06, in the high-trust range. GitLab is the vendor of the affected platform and the party that patched the email enumeration vulnerability and published remediation guidance. The T6_CONSUMER_REPUTATION_PENALTY flag reflects consumer-facing reputation signals rather than infrastructure deficiencies.
The Trust Observatory · thetrustobservatory.com · September 24, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026