In GitLab EE versions 18.0.0 up to before 18.8.9, 18.9 up to before 18.9.5, and 18.10 up to before 18.10.3 a medium severity vulnerability CVE-2026-1516 was detected. This vulnerability allows authenticated users to leak IP addresses of other users viewing Code Quality reports via specially crafted report content due to improper handling of generated code. To address this issue, users should upgrade GitLab EE to versions 18.8.9, 18.9.5, or 18.10.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1516.
Read more Developer ToolsIn GitLab EE versions 18.2 up to before 18.8.9, 18.9 up to before 18.9.5, and 18.10 up to before 18.10.3 a medium severity vulnerability CVE-2026-1101 was detected. This vulnerability allows authenticated users to cause denial of service (DoS) to the GitLab instance due to improper input validation in GraphQL queries. To address this issue, users should upgrade GitLab EE to versions 18.8.9, 18.9.5, or 18.10.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1101.
Read more Developer ToolsIn GitLab CE/EE versions 18.2 up to before 18.8.9, 18.9 up to before 18.9.5, and 18.10 up to before 18.10.3 a low severity vulnerability CVE-2026-4916 was detected. This vulnerability allows authenticated users with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations. To address this issue, users should upgrade GitLab CE/EE to versions 18.8.9, 18.9.5, or 18.10.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-4916.
Read more Developer Toolsp>In GitLab EE versions 18.2 up to before 18.8.9, 18.9 up to before 18.9.5, and 18.10 up to before 18.10.3 a medium severity vulnerability CVE-2026-4332 was detected. This vulnerability allows authenticated users to execute arbitrary JavaScript in other users’ browsers via customizable analytics dashboards due to improper input sanitization. To address this issue, users should upgrade GitLab to versions EE 18.8.9, 18.9.5, or 18.10.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-4332.
Read more Developer ToolsIn GitLab EE versions 18.6 up to before 18.8.9, 18.9 up to before 18.9.5, and 18.10 up to before 18.10.3 a medium severity vulnerability CVE-2026-2619 was detected. This vulnerability allows authenticated users with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization under certain conditions. To address this issue, users should upgrade GitLab EE to versions 18.8.9, 18.9.5, or 18.10.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2619.
Read more Developer ToolsIn GitLab CE/EE versions 18.2 up to before 18.8.9, 18.9 up to before 18.9.5, and 18.10 up to before 18.10.3 a medium severity vulnerability CVE-2026-2104 was detected. This vulnerability allows authenticated users to access confidential issues assigned to other users via CSV export due to insufficient authorization checks. To address this issue, users should upgrade GitLab CE/EE to versions 18.8.9, 18.9.5, or 18.10.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2104.
Read more Developer ToolsIn GitLab EE versions 11.3 up to before 18.8.9, 18.9 up to before 18.9.5, and 18.10 up to before 18.10.3 a medium severity vulnerability CVE-2026-1752 was detected. This vulnerability allows authenticated users with developer-role permissions to modify protected environment settings due to improper authorization checks in the API. To address this issue, users should upgrade GitLab EE to versions 18.8.9, 18.9.5, or 18.10.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1752.
Read more Developer ToolsIn GitLab CE/EE versions 16.9.6 up to before 18.8.9, 18.9 up to before 18.9.5, and 18.10 up to before 18.10.3 a high severity vulnerability CVE-2026-5173 was detected. This vulnerability allows authenticated users to invoke unintended server-side methods through WebSocket connections due to improper access control. To address this issue, users should upgrade GitLab CE/EE to versions 18.8.9, 18.9.5, or 18.10.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5173.
Read more Developer ToolsIn Gitlab versions all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 a high severity vulnerability CVE-2026-2370 was detected. An improper authorization check in Jira Connect installations could allow an authenticated user with minimal workspace permissions to obtain installation credentials and impersonate the application. To address this issue, users should update Gitlab to versions 18.8.7, 18.9.3, and 18.10.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2370.
Read more Developer Tools