vulns.co
/
GKData.io MCP

IDAuthentication and identity · 2 min read

GitLab recovery delivery lacked verified-address binding

One recovery report received USD 35,000 across two award events.

Read the primary source IDAuthentication and identityReviewed 2026-10-02

Root cause

A secondary-address recovery feature expanded delivery choices without consistently preserving verified-address ownership. The vendor attributes the regression to email verification; recovery authorization must remain bound to trusted account state as features change.

Demonstrated impact

Unauthorized password changes could lead to account takeover. Enforced second-factor authentication still prevented login, but did not prevent password reset. Offering SSO alone did not eliminate exposure when password authentication remained available.

Lessons for review

  • Bind recovery delivery to verified account state and validate security-sensitive input contracts.
  • Review recovery paths independently of primary authentication and optional SSO.
  • Vendor remediation added end-to-end reset tests covering address handling, email generation and content; review the whole recovery contract rather than one validation function.
  • Separate patch deployment from compromise assessment; apply the vendor’s incident-response guidance where compromise is suspected.

Award and evidence

USD 35,000Bug Bounty · Vendor Confirmed

USD 1,000 initial plus USD 34,000 additional award for one report. Dollar notation uses HackerOne policy currency context; cash receipt unverified.

Original public report and both award events read in the cloud browser; official vendor release notes independently corroborate the CVE, impact boundary and patched release. Re-read the vendor FAQ to distinguish secondary-address regression, second-factor and SSO boundaries, and documented regression-test coverage.

  • Award events do not establish cash settlement.
  • The report UI has no CVE field value; CVE association comes from the matching vendor advisory.
  • Detailed report publication is not the first public advisory date.
  • The advisory’s historical observation of no detected abuse on vendor-managed platforms does not establish present-day absence of compromise or the state of self-managed deployments.

Recorded timeline

Published
2025-02-26explicit · Detailed report publication, later than the vendor advisory.
Public Disclosure
2024-01-11explicit · Public vendor advisory; detailed report followed February 26, 2025.
Reported
2023-12-20explicit
Awarded
2024-01-12explicit · Final award event; initial award December 22, 2023.
Fixed
2024-01-11explicit · Public patched release. GitLab.com was patched earlier; its exact deployment date is not supplied.

Related visual models

Sources and provenance

  1. Account Takeover via Password Reset without user interactions GitLab and asterion04 · reviewed 2026-10-02
  2. GitLab Critical Security Release: 16.7.2, 16.6.4, 16.5.6 GitLab · reviewed 2026-10-02
  3. Vulnerability Disclosure Standards: Bug Bounty payment denomination HackerOne · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software