
[CIVN-2026-0389] Multiple Vulnerabilities in GitLab
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in GitLab
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
GitLab versions prior to 19.0.5, 19.1.3, and 19.2.1 for GitLab Community Edition (CE) and Enterprise Edition (EE)
Overview
Multiple vulnerabilities have been reported in GitLab CE/EE which could allow a remote attacker to gain unauthorized access to sensitive information, modify CI/CD or project configurations, bypass security restrictions, execute cross-site scripting (XSS) attacks or cause a denial-of-service (DoS) condition on the targeted system.
Target Audience:
Organizations and individuals using GitLab CE/EE instances.
Risk Assessment:
High risk of unauthorized access to sensitive information, unauthorized modification of CI/CD and project configurations, bypassing of security controls, cross-site scripting and disruption of services.
Impact Assessment:
Potential for unauthorized disclosure of sensitive information, modification of CI/CD and protected-branch configurations, bypassing of merge-request approval and governance controls, cross-site scripting attacks and denial-of-service conditions.
Description
GitLab is a web-based DevOps platform that provides tools for software developments, including source code management, continuous integration and continuous deployment. It is available in both open-source Community Edition (CE) and Enterprise Edition (EE) versions.
Multiple vulnerabilities exist in GitLab Community Edition (CE) and Enterprise Edition (EE) due to insufficient access controls, improper authorization, improper validation of user-supplied attributes, mass assignment, race conditions, improper sanitization of user-controlled input, insufficient resource throttling, improper handling of sensitive information, prompt injection in AI-assisted functionality and incorrect security-token generation.
Successful exploitation of these vulnerabilities could allow a remote attacker to gain unauthorized access to sensitive information, modify CI/CD or project configurations, bypass security restrictions, execute cross-site scripting (XSS) attacks or cause a denial-of-service (DoS) condition on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
http://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/?nav=19.2.1/
Vendor Information
GitLab
http://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/?nav=19.2.1/
References
http://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/?nav=19.2.1/
CVE Name
CVE-2026-6267
CVE-2026-12436
CVE-2026-15975
CVE-2026-13113
CVE-2026-16553
CVE-2026-6336
CVE-2026-14341
CVE-2026-3093
CVE-2026-15077
CVE-2026-15831
CVE-2026-14351
CVE-2026-4672
CVE-2026-14562
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpzRNoACgkQ3jCgcSdc
ys9kJQ//YE9DOJcNwMZf45msLqnqojWWnelDvQ1xhW0GDGjLh+91DzsYz1YlS54+
8NxPuYJV23cZXhOcwUgPOuX6Wkm+iJFS9KDMk5dbGisI6kD0FzBHdHZe8js7Snf3
G8kVRVkWrEW5JsPbl/pqlDLGGVwDCkERes3aApdCKLsC/2EJZeiyy2U/Bo2frcwz
Rz3/GMWQqwFkRnyaxQiqJPd+a5qT5/jp2Gi3j+bDCgBC4HXtfWa53oeAQkqxiwJu
nH1bIQH55wO5SfX+eTmtAwE2lxcsDONykujb+RiOHtEnaT29BL7TfyuseG3Iq7aS
aMVKAV1fUGxGQxE+4hQCOpPB1ZgtDdATvVu1IjA8kobZOedVUY/zCXT2uO/xv36x
APGzO164gzXY9HSe68wFbd3bNH+2WLw3weKX/WDqGZZIfWHCAtBDb0Kos1W6D32T
fPeeUs2GQiA4hgItj9KwfMmOjnLmOAto3pcHujFVHV3PAwrJS5q0dQSyBElsOdyY
jIc2W05HZQJmmAp2xYcVVWy9xr4dyXrDJaW9lcuMNPzb19msUDj9cPOGcfJFhi0n
Y2rqj5+MLgKUp8RDjEI6wkOx3bZUo+NRbDZf2G7PGhV0vaRk/r1/4sxXzqztjdv/
MfID2uWDDpjdaHYTCEOtPyl985M5DECTLMSHuPTyilM5cYZxf+k=
=eSRP
—–END PGP SIGNATURE—–


