logo

Security Alert: GitLab Issues Patch for High-Severity Vulnerabilities Across CE and EE

ID: 4e67b98d-69be-571c-a2fd-c0af163d5289

STIX ID: report--4e67b98d-69be-571c-a2fd-c0af163d5289

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-23

Author: Ddos

...
...

GitLab released critical security updates for Community and Enterprise editions (18.10.3, 18.9.5, 18.8.9) addressing multiple high- and medium-severity CVEs—notably an exposed WebSocket method (CVE-2026-5173), Terraform State Lock API DoS (CVE-2026-1092), GraphQL API DoS (CVE-2025-12664), plus several enterprise-impacting issues such as code quality report injection, confidential issue leakage, protected environment tampering, and privilege demotion; administrators are strongly advised to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.