DEV Community

OnaEiuspkz
OnaEiuspkz

Posted on

918,415 GitLab Assets on HTTP: Measuring the Source of Truth

918,415 GitLab Assets on HTTP: Measuring the Source of Truth

Source control is measured like any other web service, and it should be interpreted differently, because the system that stores the code also stores the credentials that build and deploy it.

The measurement

ZoomEye queries executed on 1 October 2026 at 02:33 UTC, global scope and all asset types:
| Query | Matching assets |
| --- | ---: |
| app="GitLab" | 1,328,795 |
| app="GitLab" && service="http" | 918,415 |
The HTTP-scoped figure is about 69 percent of the fingerprinted population. The measurement covers reachable assets and nothing more. It does not indicate whether an instance is self-managed or vendor-hosted, whether registration is open, or whether the deployment runs a patched version.

The advisory context

Vendor research tracks a GitLab flaw as CVE-2026-85706 with observed exploitation attempts in the wild and advises customers to upgrade promptly. The same material does not publish a mechanism, which means the response should start from the vendor advisory's version matrix rather than from inference. An attempted exploitation notice is a reason to patch, and it is not a statement that instances were successfully compromised.

Why percentages mislead here

A large share of the fingerprinted population is hosted by the vendor or by managed platforms that apply updates centrally, and those instances are outside the customer's patch responsibility even though they appear in a global service count. The number that matters to an operator is the intersection of two sets: instances the organisation runs, and instances reachable from networks it does not control.
Three refinements make the measurement actionable:

  1. Scope by organisation. app="GitLab" && service="http" combined with organisational or network conditions produces the owned list rather than a global figure.
  2. Separate the web interface from the SSH endpoint used for Git operations. Both are legitimate, and they have different exposure requirements.
  3. Check for open registration and public project visibility, since these are the features that turn a reachable instance into an intelligence source for an attacker.

Product context

GitLab's own security posture is not the subject of this article; the measurement is. ZoomEye's records for these hosts include HTTP headers, certificate details and response characteristics, which let an operator distinguish a self-managed deployment from a hosted instance and confirm which interface is answering. For an organisation running self-managed GitLab, that comparison between the public view and the internal inventory is the useful output. The count of 918,415 is context; the entry that should not be on the list is the finding.

References

  1. Tenable CVE watch listing for CVE-2026-85706, https://www.tenable.com/cve
  2. Tenable research alerts index, https://zh-cn.tenable.com/research
  3. ZoomEye measurement, queries executed 1 October 2026 at 02:33 UTC, https://www.zoomeye.ai/

Top comments (0)