GitLab Patches Multiple Duo AI, DoS, and Authorisation Vulnerabilities
ID: 649348e9-6a14-5f86-afc9-be1ab424a730
STIX ID: report--649348e9-6a14-5f86-afc9-be1ab424a730
Feed Name: GBHackers
Threat Score
GitLab released patch updates (19.0.1, 18.11.4, 18.10.7) fixing seven vulnerabilities across CE/EE—including a high-severity (CVSS 8.2) improper access control in Duo AI workflow runners (CVE-2026-4868), a Wiki DoS, and several authorization/identity issues—urging self-managed instances to upgrade immediately and review access logs and privileged workflow activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
