In authentik versions from 2021.3.1 up to but not including 2025.8.6, 2025.10.4 and 2025.12.4 a critical severity vulnerability CVE-2026-25227 was identified. This vulnerability allows a user with delegated permissions—specifically “Can view * Property Mapping” or “Can view Expression Policy”—to execute arbitrary code within the authentik server container through the test endpoint, which is intended to preview property mappings or policies. To address this issue, users should upgrade authentik to versions 2025.8.6, 2025.10.4, 2025.12.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25227.
Read more SecurityIn GitHub Copilot versions 1.0.0 before 1.5.63 a high severity vulnerability CVE-2026-21516 was identified. This vulnerability allows an unauthorized attacker to execute arbitrary code over a network due to improper neutralization of special elements used in a command (command injection). Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21516.
Read more Developer ToolsIn Kanboard versions prior to 1.2.50 a medium severity vulnerability CVE-2026-25531 was identified. This vulnerability allows an authenticated user to duplicate tasks into projects they do not have access to because the TaskCreationController::duplicateProjects() endpoint does not properly validate user permissions for target projects. To address this issue, users should upgrade Kanboard to version 1.2.50. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25531.
Read more Project ManagementIn GitLab CE/EE versions 18.6 up to but not including 18.6.6, 18.7 up to but not including 18.7.4, and 18.8 up to but not including 18.8.4 a medium severity vulnerability CVE-2026-1282 was detected. This vulnerability allows authenticated attackers to inject malicious content into project label titles due to improper neutralization of script-related HTML tags, potentially leading to cross-site scripting (XSS). To address this issue, users should upgrade GitLab CE/EE to versions 18.6.6, 18.7.4, 18.8.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1282.
Read more Developer ToolsIn GitLab CE/EE versions 18.4 up to but not including 18.6.6, 18.7 up to but not including 18.7.4, and 18.8 up to but not including 18.8.4 a high severity vulnerability CVE-2026-0958 was detected. This vulnerability allows unauthenticated attackers to cause a denial-of-service condition through memory or CPU exhaustion by bypassing JSON validation middleware limits. To address this issue, users should upgrade GitLab CE/EE to versions 18.6.6, 18.7.4, 18.8.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-0958.
Read more Developer ToolsIn Kanboard versions prior to 1.2.50 a medium severity vulnerability CVE-2026-25530 was detected. This vulnerability allows authenticated attackers to access swimlane data from projects they are not authorized to view due to a missing project-level authorization check in the `getSwimlane` API method. To address this issue, users should upgrade Kanboard to version 1.2.50 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25530.
Read more Project ManagementIn GitLab CE/EE versions 8.0 up to but not including 18.6.6, 18.7 up to but not including 18.7.4, and 18.8 up to but not including 18.8.4 a medium severity vulnerability CVE-2026-1458 was detected. This vulnerability allows unauthenticated attackers to cause a denial-of-service condition by uploading malicious files due to the allocation of resources without limits or throttling. To address this issue, users should upgrade GitLab CE/EE to versions 18.6.6, 18.7.4, 18.8.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1458.
Read more Developer ToolsIn GitLab CE/EE versions 18.7 up to but not including 18.7.4 and 18.8 up to but not including 18.8.4 a high severity vulnerability CVE-2026-1456 was detected. This vulnerability allows unauthenticated attackers to cause a denial-of-service through CPU exhaustion by submitting specially crafted Markdown files that trigger exponential processing in the Markdown preview. To address this issue, users should upgrade GitLab CE/EE to versions 18.7.4, 18.8.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1456.
Read more Developer ToolsIn GitLab EE versions 15.6 up to but not including 18.6.6, 18.7 up to but not including 18.7.4 and 18.8 up to but not including 18.8.4 a medium severity vulnerability CVE-2026-1387 was detected. This vulnerability allows authenticated attackers to cause a denial-of-service condition by uploading a malicious file and repeatedly querying it through GraphQL due to allocation of resources without limits or throttling. To address this issue, users should upgrade GitLab EE to versions 18.6.6, 18.7.4, 18.8.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1387.
Read more Developer Tools