[CIVN-2026-0284] Multiple Vulnerabilities in GitLab

By Published On: June 3, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in GitLab


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


Gitlab Community Edition (CE) and Enterprise Edition (EE) versions prior to 19.0.1, 18.11.4, and 18.10.7

Overview


Multiple vulnerabilities have been reported in GitLab CE/EE that could allow an attacker to cause Denial of Services (Dos), bypass authorization and steal sensitive information on targeted system.


Target Audience:

Organizations and individuals using GitLab CE/EE instances.


Risk Assessment:

Risk of unauthorized access, information disclosure, and denial-of-service conditions.


Impact Assessment:

Potential for unauthorized data access, data manipulation, and service disruption.


Description


GitLab is a web-based DevOps platform that provides tools for software development, including source code management, continuous integration and continuous deployment. It is available in both open-source Community Edition (CE) and Enterprise Edition (EE) versions.


These vulnerabilities exist in Gitlab Community Edition (CE) and Enterprise Edition (EE) due to improper access control in Duo AI workflow runners, incorrect name resolution, and improper authorization in Duo workflow API.


Successful exploitation of these vulnerabilities could allow an attacker to unauthorized access to sensitive information, bypass of authorization controls, denial-of-service conditions on targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-0-1-released/



Vendor Information


Gitlab

https://docs.gitlab.com/releases/patches/


References


 

https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-0-1-released/


CVE Name

CVE-2026-4868

CVE-2026-1402

CVE-2026-6713

CVE-2026-5296

CVE-2026-2601

CVE-2026-8716

CVE-2026-2710




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmogQMMACgkQ3jCgcSdc

ys/X0Q//Qh3C2+7sbxsyYMSk7AEOgZOybECJuk+qb1DOj+Bo23r9XzipXIRGt8SR

OwKXLgYqILMrzteIpFsA369ECQKnRuIGZakETwvQ/TUT1PVB9Z29DuAFA/zGAw0g

sFDiX4UWyNrKdbTZh5QbyY+vgpbWJC/hyeyNkaWyBxUSvtrKV3IzraqfvZJfQNav

K27o8dROvWe2koeuCMALjgyhJ4lrKfFtJfXdlrMJY7of4AOlphsQeNWJM34QvR48

dPi4k92UqaJcT1rVv5lkaevhPZLKzt61XlCqVKGEGmvqo5zU/GBua2WCuRDXzWAl

wpPl56QSBOmxTjycbxJQVww6Lzs5YWNROcpUF/qDTIHIdfHl5pB8slKG2Ij0Ue9W

5Dq2EEHWrMpqN4sAnfuXIrE4qZ/4uQcP4ZsLD60j+TP0br/3OjyqKSM2v3BAcnUh

v1mzHdaudVGqoeo+Nf7hm7ZNkTBngDdN44RPFv55jG1Kn7oG+NW1RhtGMoDczJJT

SHySzKsSX9FiP3ByVezbJ8OBvDmcNjDauOYC7AYyD2vQHltQfOP623X/zZELBKEg

bMaJ3NOiK6xp1jLfjxHrEUDLV24WpAqEH19u8UDh/ENvOuBx0+8HtX+CZxriWgeD

a8A4c637uy9Jc+gFGVz8EHaoAMmXrUAgby/WoR4ohL5ryTlmszQ=

=3UYM

—–END PGP SIGNATURE—–

Share this article