logo

GitLab Security Update Fixes High-Severity CVE-2026-5173, 11 Other Flaws

ID: 511daf44-586b-5668-852e-4b1d8c384f8b

STIX ID: report--511daf44-586b-5668-852e-4b1d8c384f8b

Feed Name: The Cyber Express

Threat Score
65/100

Date Published: 2026-04-10

Date Updated: 2026-05-05

Author: Ashish Khaitan

...
...

**Executive summary:** GitLab released security updates (18.10.3, 18.9.5, 18.8.9) to fix twelve vulnerabilities affecting self-managed CE/EE installations — notably CVE-2026-5173 (websocket access-control bypass, CVSS 8.5) plus multiple DoS and information-disclosure flaws — and strongly urges immediate upgrades; the advisory includes affected versions, contributors, and upgrade guidance, with no active exploitation reported in this bulletin.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.