Eliminating Vulnerability Classes at Scale in the Post-Mythos Era

A Black Hat USA 2026 talk by Jeevan Jutla

We traced every vulnerability n8n and GitLab have publicly disclosed back to the commit that fixed it. Most were repeats of problems already patched elsewhere. This pack is the executive brief and the complete evidence behind the talk.

Jeevan Jutla presenting the talk at Black Hat USA 2026

569

Findings analyzed

105

Distinct classes

67%

Peak recurrence rate

~$1.0m

Recurrence tax, GitLab

Key takeaways

67% of n8n disclosures and 58% of GitLab CVEs were repeats

The same root cause, fixed again in a different file. One GitLab class ran for 728 days across 19 engineers.

569 findings collapse to 105 root causes

What looks like an unmanageable backlog is a short list of design decisions. Fix the class once, at a shared point, and it stays fixed.

The repeats cost ~$44k at n8n and over $1M at GitLab

In bounties alone, plus 1,117 backports reapplying fixes that already existed. None of it shows up in MTTR or fix rate.

What's included

Executive brief

PDF

The written version of the talk, built for security leadership.

Complete dataset

569 findings

Every finding with its root-cause class, prevention rule, advisory, and fix commit. Explore it on this page.

Black Hat 2026 talk

Video

The full recording of the original presentation.

Explore the data

Search by class, disclosure, or fix commit, and open a class to see its prevention rule and every finding assigned to it.