Eliminating Vulnerability Classes at Scale in the Post-Mythos Era
A Black Hat USA 2026 talk by Jeevan JutlaWe traced every vulnerability n8n and GitLab have publicly disclosed back to the commit that fixed it. Most were repeats of problems already patched elsewhere. This pack is the executive brief and the complete evidence behind the talk.

569
Findings analyzed
105
Distinct classes
67%
Peak recurrence rate
~$1.0m
Recurrence tax, GitLab
Key takeaways
67% of n8n disclosures and 58% of GitLab CVEs were repeats
The same root cause, fixed again in a different file. One GitLab class ran for 728 days across 19 engineers.
569 findings collapse to 105 root causes
What looks like an unmanageable backlog is a short list of design decisions. Fix the class once, at a shared point, and it stays fixed.
The repeats cost ~$44k at n8n and over $1M at GitLab
In bounties alone, plus 1,117 backports reapplying fixes that already existed. None of it shows up in MTTR or fix rate.
What's included
Executive brief
The written version of the talk, built for security leadership.
Complete dataset
569 findings
Every finding with its root-cause class, prevention rule, advisory, and fix commit. Explore it on this page.
Black Hat 2026 talk
Video
The full recording of the original presentation.
Explore the data
Search by class, disclosure, or fix commit, and open a class to see its prevention rule and every finding assigned to it.