GitLab Critical Alert: High-Severity Flaws Allow App Impersonation and AI Token Leaks
ID: 3eb3e7d0-45d5-52a0-993f-b5687542132d
STIX ID: report--3eb3e7d0-45d5-52a0-993f-b5687542132d
Feed Name: securityonline.info
Threat Score
GitLab released a critical security advisory and patched multiple high-severity vulnerabilities affecting Community and Enterprise Editions (versions from 14.3 through 18.10), including Jira Connect impersonation (CVE-2026-2370), unauthenticated GraphQL mutation/CSRF issues (CVE-2026-3857), HTML injection (CVE-2026-2995), an AI model API token leak (CVE-2026-1724), and several denial-of-service conditions; administrators are advised to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
