PatchSiren

GitLab CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM GitLab CVE published 2026-09-15

CVE-2026-82837

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials and tokens without transiting the expected proxy due to improper authorization checks on internal data emission endpoints.

HIGH GitLab CVE published 2026-09-15

CVE-2026-13210

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to access CI/CD variables outside their intended environment scope due to improper input validation in the environment scope pattern matcher.

MEDIUM GitLab CVE published 2026-09-15

CVE-2026-12910

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to bypass SAML SSO sign-in restrictions and authenticate without SSO due to missing authentication enforcement checks. This issue is a medium-severity vulnerability that could allow authenticated use [truncated]

CRITICAL GitLab CVE published 2026-09-12

CVE-2026-87719

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass seri [truncated]

HIGH GitLab CVE published 2026-08-27

CVE-2026-75871

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T17:20:01.503Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects GitLab AI Gateway versions from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2. An authenticated user with Duo Agent Platform access could potentially redirect outbound model [truncated]

MEDIUM GitLab CVE published 2026-08-26

CVE-2026-77801

GitLab CE/EE versions 12.8 through 19.3.0 have a denial of service vulnerability due to missing object count limits. This issue allows authenticated users with low privileges to cause denial of service affecting background job processing. The vulnerability was remediated in versions 19.1.7, 19.2.5, and 19.3.1. Affected deployments should be reviewed for exposure and patched or mitigated accordingly.

MEDIUM GitLab CVE published 2026-08-26

CVE-2025-10903

GitLab EE versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 are vulnerable to denial of service via an unbounded loop triggered by specially crafted input in the SCIM user provisioning feature. This issue can be exploited by authenticated users with low privileges, potentially leading to service disruption. The vulnerability was published on 2026-08-26T14:17:06.597Z and has not [truncated]

HIGH GitLab CVE published 2026-08-23

CVE-2026-10053

CVE-2026-10053 is a path traversal vulnerability in the package registry of GitLab CE/EE affecting versions 18.8 to 19.0.5, 19.1 to 19.1.3, and 19.2 to 19.2.1. An authenticated user could exploit this vulnerability to achieve remote code execution under certain conditions. The vulnerability is caused by insufficient validation of user input in the package registry, allowing an attacker to traverse the fil [truncated]

CRITICAL GitLab CVE published 2026-08-17

CVE-2026-19478

GitLab CE/EE versions 18.2 through 19.2 are vulnerable to an issue that could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive. The CVSS score for this vulnerability is 9.4, indicating a critical severity. This issue affects all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. Administrators [truncated]

HIGH GitLab CVE published 2026-07-29

CVE-2026-6267

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling. This issue has a high severity with a CVSS score of 8.5. The vulnerability w [truncated]

MEDIUM GitLab CVE published 2026-07-29

CVE-2026-3093

CVE-2026-3093 is a vulnerability in GitLab CE/EE that allows an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL. The issue exists in versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 due to improper sanitization of user-controlled input. This vulnerability has a CVSS score of 4.7 (MEDIUM). GitLab administrators and users, security teams, and [truncated]

MEDIUM GitLab CVE published 2026-07-29

CVE-2026-16553

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of upstream requests in virtual registries. This issue is particularly concerning for GitLab EE users and administrators who manage se [truncated]

MEDIUM GitLab CVE published 2026-07-29

CVE-2026-15831

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T20:17:01.983Z and has not been modified since then. The NVD entry is currently Analyzed. GitLab EE administrators and users should prioritize patching for versions 19.1 to 19.1.2 and 19.2. Security teams should review the vulnerability and ensure proper authorization enforcement during token gene [truncated]

MEDIUM GitLab CVE published 2026-07-29

CVE-2026-15077

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T20:17:01.690Z and has not been modified since then. The NVD entry is currently Analyzed. This issue affects GitLab EE versions 19.1 before 19.1.3 and 19.2 before 19.2.1, allowing authenticated users to access information from unauthorized projects due to improper neutralization of untrusted conte [truncated]

MEDIUM GitLab CVE published 2026-07-29

CVE-2026-13113

GitLab EE versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 are affected by a race condition in approval rule processing. This vulnerability could allow an authenticated user to merge code into a protected branch without the required approvals. The issue impacts GitLab EE deployments with specific configurations of protected branches and approval rules. Affected administrators a [truncated]

HIGH GitLab CVE published 2026-07-29

CVE-2026-12436

CVE-2026-12436 is a HIGH-severity vulnerability affecting GitLab CE/EE versions 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1. An authenticated user could modify CI/CD configurations due to improper validation of user-supplied attributes when processing pipeline schedule inputs. This vulnerability allows unauthorized modification of CI/CD configurations, potentially leading to security ri [truncated]

LOW GitLab CVE published 2026-07-29

CVE-2025-14562

GitLab CE/EE versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 have an improper authorization issue. An authenticated user with developer-role permissions could commit changes to a project after being removed as a member. This issue affects GitLab users who manage access permissions and monitor project changes. The vulnerability has been remediated in the mentioned versions. GitLab u [truncated]

MEDIUM GitLab CVE published 2026-07-08

CVE-2026-8472

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with minimal access permissions to read work item metadata from private projects due to missing authorization checks. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. The [truncated]

LOW GitLab CVE published 2026-06-11

CVE-2026-9694

CVE-2026-9694 is a vulnerability in GitLab CE/EE that could allow an unauthenticated user to impersonate the GitLab Support Bot and inject arbitrary content via a specially crafted Service Desk email reply. This issue is due to improper neutralization in email template processing and affects versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.

MEDIUM GitLab CVE published 2026-06-11

CVE-2026-9204

CVE-2026-9204 is a vulnerability in GitLab CE/EE that could allow an authenticated user to read arbitrary files from the Gitaly server and access internal network resources during repository import. This issue affects versions 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.

HIGH GitLab CVE published 2026-06-11

CVE-2026-7250

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsing middleware.

LOW GitLab CVE published 2026-06-11

CVE-2026-6976

CVE-2026-6976 is a low-severity vulnerability in GitLab CE/EE that could allow an authenticated user with developer-role permissions to hide changes from merge request diff views due to improper input handling of file names. The vulnerability affects GitLab versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.

HIGH GitLab CVE published 2026-06-11

CVE-2026-6552

CVE-2026-6552 is a HIGH-severity vulnerability in GitLab EE's Group SAML identity management functionality. An authenticated user with the Group Owner role could, under certain conditions, take over another group member's GitLab account due to improper authorization.

MEDIUM GitLab CVE published 2026-06-11

CVE-2026-6269

CVE-2026-6269 is a medium-severity vulnerability in GitLab CE/EE that could allow an authenticated user with developer-role permissions to modify hidden merge requests due to incorrect authorization enforcements. The vulnerability affects all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.

LOW GitLab CVE published 2026-06-11

CVE-2026-3553

CVE-2026-3553 is a low-severity vulnerability in GitLab CE/EE that could allow an authenticated user to access confidential issue details due to incorrect authorization checks. The issue affects all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.

MEDIUM GitLab CVE published 2026-06-11

CVE-2026-1500

CVE-2026-1500 is a medium-severity vulnerability affecting GitLab CE/EE versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2. The issue could allow an authenticated user to cause denial of service due to uncontrolled resource consumption when processing a specially crafted file upload. The CVSS score for this vulnerability is 6.5, indicating a medium severity.

HIGH GitLab CVE published 2026-06-11

CVE-2026-10087

CVE-2026-10087 is a HIGH-severity vulnerability in GitLab EE. An authenticated user with developer-role permissions could execute arbitrary client-side code on behalf of a targeted user due to improper input sanitization in the Analytics Dashboard. The CVSS score is 8.7.

MEDIUM GitLab CVE published 2026-05-28

CVE-2026-9807

GitLab has remediated an authorization enforcement flaw in GitLab CE/EE where blocked Project Access Tokens could, under certain conditions, continue accessing private resources. The vulnerability affects versions 18.9 through 18.10.6, 18.11 through 18.11.3, and 19.0. Patched versions are 18.10.7, 18.11.4, and 19.0.1. The issue was reported through HackerOne and assigned CWE-863 (Incorrect Authorization). [truncated]

MEDIUM GitLab CVE published 2026-05-27

CVE-2026-8716

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended.

MEDIUM GitLab CVE published 2026-05-27

CVE-2026-6713

GitLab has remediated an authorization bypass vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) that could allow unauthorized users to enumerate private projects. The issue stems from incorrect authorization checks under certain conditions. The vulnerability affects versions 18.2 through 18.10.6, 18.11 through 18.11.3, and version 19.0.0. GitLab released patches on May 27, 2026 in [truncated]