logo

GitLab Patches Multiple Duo AI, DoS, and Authorisation Vulnerabilities

ID: 649348e9-6a14-5f86-afc9-be1ab424a730

STIX ID: report--649348e9-6a14-5f86-afc9-be1ab424a730

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Divya

...
...

GitLab released patch updates (19.0.1, 18.11.4, 18.10.7) fixing seven vulnerabilities across CE/EE—including a high-severity (CVSS 8.2) improper access control in Duo AI workflow runners (CVE-2026-4868), a Wiki DoS, and several authorization/identity issues—urging self-managed instances to upgrade immediately and review access logs and privileged workflow activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.