
[CIVN-2026-0284] Multiple Vulnerabilities in GitLab
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in GitLab
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Gitlab Community Edition (CE) and Enterprise Edition (EE) versions prior to 19.0.1, 18.11.4, and 18.10.7
Overview
Multiple vulnerabilities have been reported in GitLab CE/EE that could allow an attacker to cause Denial of Services (Dos), bypass authorization and steal sensitive information on targeted system.
Target Audience:
Organizations and individuals using GitLab CE/EE instances.
Risk Assessment:
Risk of unauthorized access, information disclosure, and denial-of-service conditions.
Impact Assessment:
Potential for unauthorized data access, data manipulation, and service disruption.
Description
GitLab is a web-based DevOps platform that provides tools for software development, including source code management, continuous integration and continuous deployment. It is available in both open-source Community Edition (CE) and Enterprise Edition (EE) versions.
These vulnerabilities exist in Gitlab Community Edition (CE) and Enterprise Edition (EE) due to improper access control in Duo AI workflow runners, incorrect name resolution, and improper authorization in Duo workflow API.
Successful exploitation of these vulnerabilities could allow an attacker to unauthorized access to sensitive information, bypass of authorization controls, denial-of-service conditions on targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-0-1-released/
Vendor Information
Gitlab
https://docs.gitlab.com/releases/patches/
References
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-0-1-released/
CVE Name
CVE-2026-4868
CVE-2026-1402
CVE-2026-6713
CVE-2026-5296
CVE-2026-2601
CVE-2026-8716
CVE-2026-2710
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmogQMMACgkQ3jCgcSdc
ys/X0Q//Qh3C2+7sbxsyYMSk7AEOgZOybECJuk+qb1DOj+Bo23r9XzipXIRGt8SR
OwKXLgYqILMrzteIpFsA369ECQKnRuIGZakETwvQ/TUT1PVB9Z29DuAFA/zGAw0g
sFDiX4UWyNrKdbTZh5QbyY+vgpbWJC/hyeyNkaWyBxUSvtrKV3IzraqfvZJfQNav
K27o8dROvWe2koeuCMALjgyhJ4lrKfFtJfXdlrMJY7of4AOlphsQeNWJM34QvR48
dPi4k92UqaJcT1rVv5lkaevhPZLKzt61XlCqVKGEGmvqo5zU/GBua2WCuRDXzWAl
wpPl56QSBOmxTjycbxJQVww6Lzs5YWNROcpUF/qDTIHIdfHl5pB8slKG2Ij0Ue9W
5Dq2EEHWrMpqN4sAnfuXIrE4qZ/4uQcP4ZsLD60j+TP0br/3OjyqKSM2v3BAcnUh
v1mzHdaudVGqoeo+Nf7hm7ZNkTBngDdN44RPFv55jG1Kn7oG+NW1RhtGMoDczJJT
SHySzKsSX9FiP3ByVezbJ8OBvDmcNjDauOYC7AYyD2vQHltQfOP623X/zZELBKEg
bMaJ3NOiK6xp1jLfjxHrEUDLV24WpAqEH19u8UDh/ENvOuBx0+8HtX+CZxriWgeD
a8A4c637uy9Jc+gFGVz8EHaoAMmXrUAgby/WoR4ohL5ryTlmszQ=
=3UYM
—–END PGP SIGNATURE—–


