logo

GitLab Critical Patch: High-Severity XSS and Unauthenticated DoS Flaws Hit Self-Managed Instances

ID: 8d2d0cee-1e9b-553f-967a-9bb59753c019

STIX ID: report--8d2d0cee-1e9b-553f-967a-9bb59753c019

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Ddos

...
...

GitLab released security updates (18.11.3, 18.10.6, 18.9.7) addressing multiple high-severity vulnerabilities — including several XSS flaws (many with CVSS ~8.7), unauthenticated DoS vectors, memory exhaustion via CSV parsing, authorization failures exposing private issue content, and package-protection bypasses — which could allow script execution, service outages, and unauthorized access on self-managed instances; administrators should apply the patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.