GitLab Product Security Update Advisory
A security update has been released to address vulnerabilities found in GitLab products. The vulnerability addressed is CVE-2026-13320, a cross-site scripting (XSS) vulnerability (a vulnerability that allows malicious scripts to be injected into and executed on a web page) in GitLab CE/EE—a cross-site scripting (XSS) vulnerability (a vulnerability that allows
GitLab Product Security Update Advisory
A security update has been released to address vulnerabilities found in GitLab products. The vulnerabilities fixed are as follows: CVE-2026-10086: A cross-site scripting (XSS) vulnerability in GitLab EE (a vulnerability that allows malicious scripts to be injected into web pages). CVE-2026-10712: A cross-site scripting (XSS) vulnerability in GitLab CE/EE. CVE-2026-12053:
GitLab product security update advisory
GitLab has released a security update that addresses multiple vulnerabilities in its products. the targeted vulnerabilities are CVE-2026-6552, CVE-2026-7250, CVE-2026-8589, and CVE-2026-10087. CVE-2026-10087 is a cross-site scripting (XSS) vulnerability in GitLab EE that allows malicious script to be injected into web pages. CVE-2026-6552 is an access control laxity vulnerability in
GitLab product security update advisory
GitLab product security update advisory GitLab has released a security update to address a vulnerability in GitLab EE. Resolved vulnerabilities CVE-2026-4868: An access control flaw in GitLab EE. CVE-2026-7481: A cross-site scripting (XSS) vulnerability in GitLab EE that could allow malicious script to be injected into a web page. Affected
GitLab product security update advisory
Overview A security update has been released to address vulnerabilities in GitLab products. users of these products should update to the latest version of the patch. Affected Products and Versions CVE-2025-14869, CVE-2025-14870: GitLab CE/EE 18.5 and later but not earlier than 18.9.7, 18.10 and later but not earlier than 18.10.6,
GitLab Product Security Update Advisory (CVE-2026-5173)
Overview. A vulnerability (CVE-2026-5173) was reported in the GitLab product that allows server-side method calls due to lack of WebSocket access control. Affected Versions. GitLab CE/EE versions 16.9.6 and above but below 18.8.9 are affected. GitLab CE/EE versions 18.9 and above but below 18.9.5 are affected. GitLab CE/EE versions 18.10
GitLab product security update advisory
Summary. Cross-site request forgery in the GraphQL API (CVE-2026-4922), cross-site scripting in Storybook (CVE-2026-5262), and poor path equivalence handling in Web IDE assets (CVE-2026-5816) have been announced in GitLab CE/EE. affected products span multiple 16.x-18.x version bands, with specific version ranges for each vulnerability. the vulnerabilities are resolved through updates
GitLab product security update advisory
overview We have released security updates that address vulnerabilities in GitLab products. users of affected products are encouraged to update to the latest version. affected products CVE-2025-12664 GitLab CE/EE Version: 13.0 and above but below 18.8.9GitLab CE/EE Versions: 18.9 and above but below 18.9.5GitLab CE/EE Version: 18.10 or later but
GitLab Product Security Update Advisory (CVE-2026-2370)
overview We have released security updates to address vulnerabilities in GitLab products. users of affected products are encouraged to update to the latest version. affected products CVE-2026-2370 GitLab CE/EE Versions: 14.3 and above but below 18.8.7GitLab CE/EE Versions: 18.9 and later but not earlier than 18.9.3GitLab CE/EE version: 18.10 or
GitLab product security update advisory
overview We have released security updates to address vulnerabilities in GitLab products. users of affected products are encouraged to update to the latest version. affected products CVE-2026-2995 GitLab EE Version: 15.4 and above but below 18.8.7GitLab EE Version: 18.9 and above but below 18.9.3GitLab EE version: 18.10 or later but

