CRITICALAdvisoryJul 27, 2026
Action required
Immediately verify all self-managed GitLab instances are running the latest patched version of the Oj gem. Check git server logs and audit trails for suspicious Jupyter notebook commits and diff requests from authenticated users. If unpatched, restrict Jupyter notebook diff functionality or isolate instances until patching is complete.
Affected products
GitLabOjdepthfirst