GitLab Security Update Fixes High-Severity CVE-2026-5173, 11 Other Flaws
ID: 511daf44-586b-5668-852e-4b1d8c384f8b
STIX ID: report--511daf44-586b-5668-852e-4b1d8c384f8b
Feed Name: The Cyber Express
Threat Score
**Executive summary:** GitLab released security updates (18.10.3, 18.9.5, 18.8.9) to fix twelve vulnerabilities affecting self-managed CE/EE installations — notably CVE-2026-5173 (websocket access-control bypass, CVSS 8.5) plus multiple DoS and information-disclosure flaws — and strongly urges immediate upgrades; the advisory includes affected versions, contributors, and upgrade guidance, with no active exploitation reported in this bulletin.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
