GitLab Addresses Multiple Vulnerabilities Linked to DoS and Code Injection
ID: b6aa32bd-4258-5958-bc4e-aabd661d5ab5
STIX ID: report--b6aa32bd-4258-5958-bc4e-aabd661d5ab5
Feed Name: GBHackers
GitLab released urgent security updates for Community and Enterprise Editions to address twelve vulnerabilities—most notably CVE-2026-5173 (high, CVSS 8.5) which exposes a websocket method enabling unintended server-side execution. The advisory covers multiple high- and medium-severity issues (DoS in Terraform state lock and GraphQL APIs, code injection leaking viewer IPs, XSS, information disclosure, and improper access controls) affecting a range of self-managed versions; GitLab.com and GitLab Dedicated customers are already protected. Administrators of self-hosted instances are urged to upgrade to the fixed releases (18.10.3, 18.9.5, 18.8.9) to mitigate exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
