GitLab Multiple Vulnerabilities
Release Date: 26 Mar 2026
RISK: Medium Risk
TYPE: Servers - Other Servers
Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, spoofing, sensitive information disclosure, cross-site scripting, data manipulation and security restriction bypass on the targeted system.
Impact
- Denial of Service
- Security Restriction Bypass
- Cross-Site Scripting
- Data Manipulation
- Information Disclosure
- Elevation of Privilege
- Spoofing
System / Technologies affected
- GitLab Community Edition (CE) versions prior to 18.10.1, 18.9.3, 18.8.7
- GitLab Enterprise Edition (EE) versions prior to 18.10.1, 18.9.3, 18.8.7
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
Vulnerability Identifier
- CVE-2025-13078
- CVE-2025-13436
- CVE-2025-14595
- CVE-2026-1724
- CVE-2026-2370
- CVE-2026-2726
- CVE-2026-2745
- CVE-2026-2973
- CVE-2026-2995
- CVE-2026-3857
- CVE-2026-3988
- CVE-2026-4363
沒有留言:
發佈留言