These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials and tokens without transiting the expected proxy due to improper authorization checks on internal data emission endpoints.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to access CI/CD variables outside their intended environment scope due to improper input validation in the environment scope pattern matcher.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to bypass SAML SSO sign-in restrictions and authenticate without SSO due to missing authentication enforcement checks. This issue is a medium-severity vulnerability that could allow authenticated use [truncated]
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass seri [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T17:20:01.503Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects GitLab AI Gateway versions from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2. An authenticated user with Duo Agent Platform access could potentially redirect outbound model [truncated]
GitLab CE/EE versions 12.8 through 19.3.0 have a denial of service vulnerability due to missing object count limits. This issue allows authenticated users with low privileges to cause denial of service affecting background job processing. The vulnerability was remediated in versions 19.1.7, 19.2.5, and 19.3.1. Affected deployments should be reviewed for exposure and patched or mitigated accordingly.
GitLab EE versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 are vulnerable to denial of service via an unbounded loop triggered by specially crafted input in the SCIM user provisioning feature. This issue can be exploited by authenticated users with low privileges, potentially leading to service disruption. The vulnerability was published on 2026-08-26T14:17:06.597Z and has not [truncated]
CVE-2026-10053 is a path traversal vulnerability in the package registry of GitLab CE/EE affecting versions 18.8 to 19.0.5, 19.1 to 19.1.3, and 19.2 to 19.2.1. An authenticated user could exploit this vulnerability to achieve remote code execution under certain conditions. The vulnerability is caused by insufficient validation of user input in the package registry, allowing an attacker to traverse the fil [truncated]
GitLab CE/EE versions 18.2 through 19.2 are vulnerable to an issue that could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive. The CVSS score for this vulnerability is 9.4, indicating a critical severity. This issue affects all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. Administrators [truncated]
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling. This issue has a high severity with a CVSS score of 8.5. The vulnerability w [truncated]
CVE-2026-3093 is a vulnerability in GitLab CE/EE that allows an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL. The issue exists in versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 due to improper sanitization of user-controlled input. This vulnerability has a CVSS score of 4.7 (MEDIUM). GitLab administrators and users, security teams, and [truncated]
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of upstream requests in virtual registries. This issue is particularly concerning for GitLab EE users and administrators who manage se [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T20:17:01.983Z and has not been modified since then. The NVD entry is currently Analyzed. GitLab EE administrators and users should prioritize patching for versions 19.1 to 19.1.2 and 19.2. Security teams should review the vulnerability and ensure proper authorization enforcement during token gene [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T20:17:01.690Z and has not been modified since then. The NVD entry is currently Analyzed. This issue affects GitLab EE versions 19.1 before 19.1.3 and 19.2 before 19.2.1, allowing authenticated users to access information from unauthorized projects due to improper neutralization of untrusted conte [truncated]
GitLab EE versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 are affected by a race condition in approval rule processing. This vulnerability could allow an authenticated user to merge code into a protected branch without the required approvals. The issue impacts GitLab EE deployments with specific configurations of protected branches and approval rules. Affected administrators a [truncated]
CVE-2026-12436 is a HIGH-severity vulnerability affecting GitLab CE/EE versions 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1. An authenticated user could modify CI/CD configurations due to improper validation of user-supplied attributes when processing pipeline schedule inputs. This vulnerability allows unauthorized modification of CI/CD configurations, potentially leading to security ri [truncated]
GitLab CE/EE versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 have an improper authorization issue. An authenticated user with developer-role permissions could commit changes to a project after being removed as a member. This issue affects GitLab users who manage access permissions and monitor project changes. The vulnerability has been remediated in the mentioned versions. GitLab u [truncated]
GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with minimal access permissions to read work item metadata from private projects due to missing authorization checks. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. The [truncated]
CVE-2026-9694 is a vulnerability in GitLab CE/EE that could allow an unauthenticated user to impersonate the GitLab Support Bot and inject arbitrary content via a specially crafted Service Desk email reply. This issue is due to improper neutralization in email template processing and affects versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.
CVE-2026-9204 is a vulnerability in GitLab CE/EE that could allow an authenticated user to read arbitrary files from the Gitaly server and access internal network resources during repository import. This issue affects versions 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsing middleware.
CVE-2026-6976 is a low-severity vulnerability in GitLab CE/EE that could allow an authenticated user with developer-role permissions to hide changes from merge request diff views due to improper input handling of file names. The vulnerability affects GitLab versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.
CVE-2026-6552 is a HIGH-severity vulnerability in GitLab EE's Group SAML identity management functionality. An authenticated user with the Group Owner role could, under certain conditions, take over another group member's GitLab account due to improper authorization.
CVE-2026-6269 is a medium-severity vulnerability in GitLab CE/EE that could allow an authenticated user with developer-role permissions to modify hidden merge requests due to incorrect authorization enforcements. The vulnerability affects all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.
CVE-2026-3553 is a low-severity vulnerability in GitLab CE/EE that could allow an authenticated user to access confidential issue details due to incorrect authorization checks. The issue affects all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.
CVE-2026-1500 is a medium-severity vulnerability affecting GitLab CE/EE versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2. The issue could allow an authenticated user to cause denial of service due to uncontrolled resource consumption when processing a specially crafted file upload. The CVSS score for this vulnerability is 6.5, indicating a medium severity.
CVE-2026-10087 is a HIGH-severity vulnerability in GitLab EE. An authenticated user with developer-role permissions could execute arbitrary client-side code on behalf of a targeted user due to improper input sanitization in the Analytics Dashboard. The CVSS score is 8.7.
GitLab has remediated an authorization enforcement flaw in GitLab CE/EE where blocked Project Access Tokens could, under certain conditions, continue accessing private resources. The vulnerability affects versions 18.9 through 18.10.6, 18.11 through 18.11.3, and 19.0. Patched versions are 18.10.7, 18.11.4, and 19.0.1. The issue was reported through HackerOne and assigned CWE-863 (Incorrect Authorization). [truncated]
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended.
GitLab has remediated an authorization bypass vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) that could allow unauthorized users to enumerate private projects. The issue stems from incorrect authorization checks under certain conditions. The vulnerability affects versions 18.2 through 18.10.6, 18.11 through 18.11.3, and version 19.0.0. GitLab released patches on May 27, 2026 in [truncated]