Security Alert: GitLab Issues Patch for High-Severity Vulnerabilities Across CE and EE
ID: 4e67b98d-69be-571c-a2fd-c0af163d5289
STIX ID: report--4e67b98d-69be-571c-a2fd-c0af163d5289
Feed Name: securityonline.info
GitLab released critical security updates for Community and Enterprise editions (18.10.3, 18.9.5, 18.8.9) addressing multiple high- and medium-severity CVEs—notably an exposed WebSocket method (CVE-2026-5173), Terraform State Lock API DoS (CVE-2026-1092), GraphQL API DoS (CVE-2025-12664), plus several enterprise-impacting issues such as code quality report injection, confidential issue leakage, protected environment tampering, and privilege demotion; administrators are strongly advised to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
