<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – GitLab</title>
  <link>https://cvedaily.com/pages/tags/gitlab.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/gitlab.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – GitLab</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:40 +0000</lastBuildDate>
  <item>
    <title>[Low] CVE-2026-10078 – A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10078</guid>
    <pubDate>Fri, 29 May 2026 11:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10078</strong></p>
  <p>A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, specifically client_id and client_secret, to be transmitted as plaintext in URL query parameters during POST requests to the GitLab endpoint. This insecure transmission can lead to the disclosure of these credentials in various system logs, such as server access logs, reverse proxy…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-598</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9807 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9807</guid>
    <pubDate>Thu, 28 May 2026 09:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9807</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed a blocked Project Access Token to continue accessing private resources due to incorrect authorization enforcement.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8716 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8716</guid>
    <pubDate>Wed, 27 May 2026 19:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8716</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-706</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6713 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6713</guid>
    <pubDate>Wed, 27 May 2026 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6713</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an unauthorized user to enumerate private projects due to incorrect authorization checks.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5296 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5296</guid>
    <pubDate>Wed, 27 May 2026 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5296</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that when foundational flows were enabled at the group level, could have allowed an authenticated user with developer-role permissions to bypass flow restrictions under certain conditions.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4868 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4868</guid>
    <pubDate>Wed, 27 May 2026 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4868</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authenticated user to cause specific Duo AI workflows to run under another user's identity due to improper user identity resolution when triggering Duo AI workflow runners.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2601 – GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2601</guid>
    <pubDate>Wed, 27 May 2026 19:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2601</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to access sensitive deployment data on projects due to improper authorization checks.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1402 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1402</guid>
    <pubDate>Wed, 27 May 2026 19:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1402</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to cause denial of service due to insufficient validation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44895 – GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44895</guid>
    <pubDate>Tue, 26 May 2026 22:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44895</strong></p>
  <p>GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-Control-Allow-Origin: * on every response. The structural defect is that the SSE server stands up a stateful, mutation-capable RPC endpoint that is backed by the operator's GITLAB_PERSONAL_ACCESS_TOKEN without any inboun…</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3515 – A vulnerability in the `GitHubRepository` block of the `prefect-github` integrat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3515</guid>
    <pubDate>Sun, 24 May 2026 05:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3515</strong></p>
  <p>A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line options via the `reference` field. The `reference` field is concatenated directly into a `git clone` command string without proper sanitization, and then parsed by `shlex.split()`. This enables injection of options such as `-c`, lead…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3117 – Mattermost Plugins versions &lt;=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly che...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3117</guid>
    <pubDate>Mon, 18 May 2026 09:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3117</strong></p>
  <p>Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin which allows normal users to uninstall instances or setup webhook connections via the {{gitlab instance {option}}} or the {{/gitlab webhook {option}}} commands. Mattermost Advisory ID: MMSA-2026-00600</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8280 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8280</guid>
    <pubDate>Thu, 14 May 2026 06:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8280</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to cause denial of service through excessive memory consumption due to improper input validation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8144 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8144</guid>
    <pubDate>Thu, 14 May 2026 06:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8144</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with project membership to enumerate private group members due to missing authorization checks.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7481 – GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7481</guid>
    <pubDate>Thu, 14 May 2026 06:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7481</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to execute arbitrary JavaScript in other users' browsers due to improper input sanitization.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-7471 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7471</guid>
    <pubDate>Thu, 14 May 2026 06:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-7471</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with control of a virtual registry upstream to make requests to internal hosts due to improper validation.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7377 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7377</guid>
    <pubDate>Thu, 14 May 2026 06:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7377</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-6883 – GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6883</guid>
    <pubDate>Thu, 14 May 2026 06:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-6883</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to bypass merge request approval requirements due to improper cleanup of orphaned policy records.</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6335 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6335</guid>
    <pubDate>Thu, 14 May 2026 06:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6335</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.3 that under certain conditions could have allowed an authenticated user to execute arbitrary code in another user's browser session due to improper sanitization.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6073 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6073</guid>
    <pubDate>Thu, 14 May 2026 06:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6073</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to execute arbitrary JavaScript in other users' browsers due to improper input sanitization.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6063 – GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6063</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6063</guid>
    <pubDate>Thu, 14 May 2026 06:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6063</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that under certain conditions could have allowed an authenticated user with developer-role permissions to remove code owner approval rules from merge requests due to improper access control.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6063">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4527 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4527</guid>
    <pubDate>Thu, 14 May 2026 06:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4527</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to create unauthorized Jira subscriptions for a targeted user's namespace via a specially crafted link due to missing CSRF protection.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4524 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4524</guid>
    <pubDate>Thu, 14 May 2026 06:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4524</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to access confidential issue content in public projects without proper authorization due to improper authorization checks.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3607 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3607</guid>
    <pubDate>Thu, 14 May 2026 06:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3607</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to bypass package protection rules due to improper access control.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1280</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3160 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3160</guid>
    <pubDate>Thu, 14 May 2026 06:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3160</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to view Jira issues outside the configured project scope due to an integration filter functioning only as a display control rather than enforcing access boundaries as specified.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-441</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3074 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3074</guid>
    <pubDate>Thu, 14 May 2026 06:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3074</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to download private debugging symbols from inaccessible projects due to improper access control.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3073 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3073</guid>
    <pubDate>Thu, 14 May 2026 06:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3073</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to bypass PyPI package protection rules and upload restricted packages due to improper authorization checks.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-2900 – GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2900</guid>
    <pubDate>Thu, 14 May 2026 06:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-2900</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that when instance-level approval rule editing prevention was enabled, could have allowed an authenticated user with Maintainer permissions to modify or delete project approval rules due to missing authorization checks.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1659 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1659</guid>
    <pubDate>Thu, 14 May 2026 06:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1659</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted requests due to insufficient input validation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1338 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1338</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1338</guid>
    <pubDate>Thu, 14 May 2026 06:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1338</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to delete protected container registry tags due to improper authorization checks.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1338">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1322 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1322</guid>
    <pubDate>Thu, 14 May 2026 06:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1322</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with a read_api scoped OAuth application to create issues and add comments to issues in private projects due to improper authorization.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-840</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1184 – GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1184</guid>
    <pubDate>Thu, 14 May 2026 06:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1184</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by uploading a specially crafted file due to improper validation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14870 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14870</guid>
    <pubDate>Thu, 14 May 2026 06:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14870</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted JSON payloads due to insufficient input validation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14869 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14869</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14869</guid>
    <pubDate>Thu, 14 May 2026 06:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14869</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted payloads on certain API endpoints.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14869">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13874 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13874</guid>
    <pubDate>Thu, 14 May 2026 06:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13874</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with Guest permissions to view issues in projects they were not authorized to access.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12669 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12669</guid>
    <pubDate>Thu, 14 May 2026 06:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12669</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to inject HTML and JavaScript into email notifications sent to other users due to improper input sanitization.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44931 – The newly introduced  RecordUsage D-Bus method https://gitlab.freedesktop.org/pw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44931</guid>
    <pubDate>Wed, 13 May 2026 13:01:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44931</strong></p>
  <p>The newly introduced  RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalcontent-timer/child-timer-service.c  in malcontent-timerd allows arbitrary users in the system to slowly fill up disk space in /var/lib/malcontent-timerd</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-42195 – draw.io is a configurable diagramming and whiteboarding application. Prior to ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42195</guid>
    <pubDate>Fri, 08 May 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-42195</strong></p>
  <p>draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts a ?gitlab= URL parameter that overrides the GitLab server URL used during OAuth sign-in. A crafted link causes the user's click on draw.io's "Authorize in GitLab" dialog to open a popup on the attacker-controlled host instead of gitlab.com. This can lead to credential fishing a…</p>
  <p><strong>CVSS:</strong> 3.4 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6515 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6515</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6515</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed a user to use invalidated or incorrectly scoped credentials to access Virtual Registries under certain conditions.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5816 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5816</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5816</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-41</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5377 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5377</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5377</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that could have allowed an authenticated user to access titles of confidential or private issues in public projects due to improper access control in the issue description rendering process.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5262 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5262</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5262</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5262</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5262">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4922 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4922</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4922</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-3254 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3254</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-3254</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to load unauthorized content into another user's browser due to improper input validation in the Mermaid sandbox.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1660 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1660</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1660</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to cause denial of service when importing issues due to improper input validation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-9957 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9957</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-9957</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user with project owner permissions to bypass group fork prevention settings due to improper authorization checks.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-6016 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6016</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-6016</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service due to insufficient resource allocation limits when retrieving notes under certain conditions.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3922 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3922</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3922</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service by overwhelming system resources under certain conditions due to insufficient resource allocation limits in the GraphQL API.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0186 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0186</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0186</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service under certain conditions by exhausting server resources by making crafted requests to a discussions endpoint.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40161 – Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40161</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40161</guid>
    <pubDate>Tue, 21 Apr 2026 17:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40161</strong></p>
  <p>Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled serverURL when the user omits the token parameter. A tenant with TaskRun or PipelineRun create permission can e…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40161">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5173 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5173</guid>
    <pubDate>Wed, 08 Apr 2026 23:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5173</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-749</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-4916 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4916</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4916</guid>
    <pubDate>Wed, 08 Apr 2026 23:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-4916</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4916">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4332 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4332</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4332</guid>
    <pubDate>Wed, 08 Apr 2026 23:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4332</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4332">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2619 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2619</guid>
    <pubDate>Wed, 08 Apr 2026 23:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2619</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2104 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2104</guid>
    <pubDate>Wed, 08 Apr 2026 23:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2104</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to access confidential issues assigned to other users via CSV export due to insufficient authorization checks.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1752 – GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1752</guid>
    <pubDate>Wed, 08 Apr 2026 23:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1752</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with developer-role permissions to modify protected environment settings due to improper authorization checks in the API.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1516 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1516</guid>
    <pubDate>Wed, 08 Apr 2026 23:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1516</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of users viewing the report via specially crafted content.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1101 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1101</guid>
    <pubDate>Wed, 08 Apr 2026 23:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1101</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to cause denial of service to the GitLab instance due to improper input validation in GraphQL queries.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1092 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1092</guid>
    <pubDate>Wed, 08 Apr 2026 23:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1092</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service due to improper input validation of JSON payloads.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9484 – GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9484</guid>
    <pubDate>Wed, 08 Apr 2026 23:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9484</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user to have access to other users' email addresses via certain GraphQL queries.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12664 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12664</guid>
    <pubDate>Wed, 08 Apr 2026 23:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12664</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2370 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2370</guid>
    <pubDate>Mon, 30 Mar 2026 00:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2370</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with minimal workspace permissions to obtain installation credentials and impersonate the GitLab app due to improper authorization checks.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-233</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3988 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3988</guid>
    <pubDate>Wed, 25 Mar 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3988</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to cause a denial of service by making the GitLab instance unresponsive due to improper input validation in GraphQL request processing.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3857 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3857</guid>
    <pubDate>Wed, 25 Mar 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3857</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to execute arbitrary GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2995 – GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2995</guid>
    <pubDate>Wed, 25 Mar 2026 17:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2995</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to add email addresses to targeted user accounts due to improper sanitization of HTML content.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2973 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2973</guid>
    <pubDate>Wed, 25 Mar 2026 17:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2973</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to execute arbitrary JavaScript in a user's browser due to improper sanitization of entity-encoded content in Mermaid diagrams.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2745 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2745</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2745</guid>
    <pubDate>Wed, 25 Mar 2026 17:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2745</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to bypass WebAuthn two-factor authentication and gain unauthorized access to user accounts due to inconsistent input validation in the authentication process.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2745">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2726 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2726</guid>
    <pubDate>Wed, 25 Mar 2026 17:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2726</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to perform unauthorized actions on merge requests in other projects due to improper access control during cross-repository operations.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1724 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1724</guid>
    <pubDate>Wed, 25 Mar 2026 17:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1724</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to access API tokens of self-hosted AI models due to improper access control.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14595 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14595</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14595</guid>
    <pubDate>Wed, 25 Mar 2026 17:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14595</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user with Planner role to view security category metadata and attributes in group security configuration due to improper access control</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14595">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13436 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13436</guid>
    <pubDate>Wed, 25 Mar 2026 17:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13436</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when handling certain CI-related inputs.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13078 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13078</guid>
    <pubDate>Wed, 25 Mar 2026 17:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13078</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when processing certain webhook configuration inputs.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-4363 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4363</guid>
    <pubDate>Wed, 25 Mar 2026 15:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-4363</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user to gain unauthorized access to resources due to improper caching of authorization decisions.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1182 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1182</guid>
    <pubDate>Thu, 12 Mar 2026 02:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1182</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to gain unauthorized access to confidential issue title created in public projects under certain circumstances.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-212</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12555 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12555</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12555</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that, under certain conditions, could have allowed an authenticated user to access previous pipeline job information on projects with repository and CI/CD disabled due to improper authorization checks.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3848 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3848</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3848</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to make unintended internal requests through proxy environments under certain conditions due to improper input validation in import functionality.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-93</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1732 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1732</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1732</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose confidential issue titles due to improper filtering under certain circumstances.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-212</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1663 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1663</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1663</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with group import permissions to create labels in private projects due to improper authorization validation in the group import process under certain circumstances.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1230 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1230</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1230</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause repository downloads to contain different code than displayed in the web interface due to incorrect validation of branch references under certain circumstances.</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-706</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1090 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1090</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1090</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inject JavaScript in a browser due to improper sanitization of placeholder content in markdown processing.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1069 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1069</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1069</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by sending specially crafted GraphQL requests due to uncontrolled recursion under certain circumstances.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0602 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0602</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0602</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose metadata from private issues, merge requests, epics, milestones, or commits due to improper filtering in the snippet rendering process under certain circumstances.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14513 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14513</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14513</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially crafted JSON payloads in the protected branches API.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13929 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13929</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13929</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by issuing specially crafted requests to repository archive endpoints under certain conditions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13690 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13690</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13690</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause a denial of service condition due to improper input validation on webhook custom header names under certain conditions.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-12704 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12704</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12704</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-12704</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to access Virtual Registry data in groups where they are not members due to improper authorization under certain conditions.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12704">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-12697 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12697</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-12697</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API credentials under certain conditions.</p>
  <p><strong>CVSS:</strong> 2.2 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12576 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12576</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12576</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that under certain conditions could have allowed an authenticated user to cause a denial of service due to improper handling of webhook response data.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2845 – An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2845</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2845</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an authenticated user to cause denial of service by exploiting a Bitbucket Server import endpoint via repeatedly sending large responses.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1747 – GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1747</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1747</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1747</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-role users with insufficient privileges to make unauthorized modifications to protected Conan packages.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1747">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1725 – GitLab has remediated an issue in GitLab CE/EE affecting versions from 18.9 befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1725</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1725</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting versions from 18.9 before 18.9.1 that could have under certain conditions, allowed an unauthenticated user to cause denial of service by sending specially crafted requests to a CI jobs API endpoint.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1662 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1662</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1662</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause Denial of Service by sending specially crafted requests to the Jira events endpoint.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1388 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1388</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1388</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause regular expression denial of service by sending specially crafted input to a merge request endpoint under certain conditions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0752 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0752</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0752</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that under certain circumstances, could have allowed an unauthenticated user to inject arbitrary scripts into the Mermaid sandbox UI.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14511 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14511</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14511</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted files to the container registry event endpoint under certain conditions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3525 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3525</guid>
    <pubDate>Wed, 25 Feb 2026 20:21:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3525</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have, under certain circumstances, allowed an authenticated user with certain access to cause Denial of Service by creating specially crafted CI triggers via the API.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14103 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14103</guid>
    <pubDate>Wed, 25 Feb 2026 20:20:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14103</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthorized user with Developer-role permissions to set pipeline variables for manually triggered jobs under certain conditions.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1458 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1458</guid>
    <pubDate>Wed, 11 Feb 2026 12:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1458</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service by uploading malicious files.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1456 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1456</guid>
    <pubDate>Wed, 11 Feb 2026 12:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1456</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1387 – GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1387</guid>
    <pubDate>Wed, 11 Feb 2026 12:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1387</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to cause Denial of Service by uploading a malicious file and repeatedly querying it through GraphQl.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-1282 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1282</guid>
    <pubDate>Wed, 11 Feb 2026 12:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-1282</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to inject malicious content into project labels titles.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1282">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
