In GitLab CE/EE versions 18.9 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 a medium severity vulnerability CVE-2026-9807 was detected. This vulnerability allows an attacker using a blocked Project Access Token to continue accessing private resources. This occurs due to incorrect authorization enforcement within the application under certain conditions. To address this issue, users should upgrade GitLab CE/EE to versions 18.10.7, 18.11.4, or 19.0.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-9807.
Read more Developer ToolsIn Portainer Community Edition versions 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0 a high severity vulnerability CVE-2026-44883 was detected. This vulnerability allows an attacker to obtain full user privileges by harvesting leaked authentication tokens. This occurs because the authentication middleware accepts JWT bearer tokens passed as the “?token=<JWT>” URL query parameter on any authenticated API endpoint. Consequently, these sensitive tokens can be exposed in reverse-proxy access logs, browser history, or HTTP Referer headers. To address this issue, users should upgrade Portainer Community Edition to versions 2.33.8, 2.39.2, or 2.41.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-44883.
Read more Developer ToolsIn GitLab CE/EE versions 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 a medium severity vulnerability CVE-2026-6713 was detected. This vulnerability allows an unauthorized user to enumerate private projects under certain conditions. This occurs due to incorrect authorization checks within the application. To address this issue, users should upgrade GitLab CE/EE to versions 18.10.7, 18.11.4, or 19.0.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-6713.
Read more Developer ToolsIn GitLab CE/EE versions 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 a medium severity vulnerability CVE-2026-8716 was detected. This vulnerability allows an authenticated user to access CI data from a different ref type than intended under certain conditions. This occurs due to the use of an incorrectly-resolved name or reference within the application. To address this issue, users should upgrade GitLab CE/EE to versions 18.10.7, 18.11.4, or 19.0.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-8716.
Read more Developer ToolsIn Plane versions 1.3.0 and below a medium severity vulnerability CVE-2026-40102 was detected. This vulnerability allows an authenticated workspace member to extract sensitive data, including bcrypt password hashes, API tokens, and user email addresses. This occurs due to an Object-Relational Mapping (ORM) Field Reference Injection flaw in the SavedAnalyticEndpoint, where the user-controlled “segment” query parameter is passed directly to a Django F() expression without validation. By crafting a specific segment value, an attacker can traverse foreign-key relationships (e.g., workspace__owner__password) and have the referenced field values returned directly in the JSON response. To address this issue, users should upgrade Plane to version 1.3.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-40102.
Read more Developer ToolsIn GitLab EE versions 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 a medium severity vulnerability CVE-2026-6063 was detected. This vulnerability allows an authenticated user with developer-role permissions to remove code owner approval rules from merge requests under certain conditions due to improper access control. To address this issue, users should upgrade GitLab EE to versions 18.9.7, 18.10.6, or 18.11.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-6063.
Read more Developer ToolsIn GitBucket version 4.23.1 a critical severity vulnerability CVE-2018-25332 was detected. This vulnerability allows an unauthenticated attacker to execute arbitrary commands remotely (RCE). This occurs due to weak secret token generation and insecure file upload functionality. An attacker can brute-force the Blowfish encryption key, upload a malicious JAR plugin via the git-lfs endpoint, and execute system commands through an exposed exploit endpoint. To address this issue, users should upgrade GitBucket to version [укажите исправленную версию]. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2018-25332.
Read more Developer ToolsIn Argo Workflows versions prior to 3.7.14 and 4.0.5 a high severity vulnerability CVE-2026-42296 was detected. This vulnerability, which is an incomplete fix for CVE-2026-31892, allows users with “create Workflow” permissions to bypass the template Referencing Strict mode. By exploiting this, attackers can gain host network access, switch service accounts, override pod security contexts, add tolerations to schedule on control-plane nodes, or enable service account token mounting. Environments relying solely on Argo’s Strict mode without additional Kubernetes-level controls (like PodSecurity admission) are fully exposed. To address this issue, users should upgrade Argo Workflows to versions 3.7.14 or 4.0.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-42296.
Read more Developer ToolsIn etcd versions prior to 3.4.44, 3.5.30, and 3.6.11 a medium severity vulnerability CVE-2026-44283 was detected. This vulnerability allows an authenticated user without sufficient read or lease-related permissions to access unauthorized data or attach leases. This occurs because read access via PrevKv or lease attachments in Put requests within transaction operations can bypass RBAC authorization checks. To address this issue, users should upgrade etcd to versions 3.4.44, 3.5.30, or 3.6.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-44283.
Read more Developer Tools