news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans GitLab (26 août 2026)

HighCVSS 8.1
Summary

Multiple vulnerabilities have been discovered in GitLab, allowing attackers to potentially execute arbitrary code remotely, cause a denial-of-service, and compromise data confidentiality. These vulnerabilities affect specific versions of the GitLab Community and Enterprise editions, requiring immediate patching to mitigate the risks.

Multiple security vulnerabilities have been identified within GitLab. These flaws could enable an attacker to execute arbitrary code remotely, leading to a denial-of-service condition and potentially compromising sensitive data. The vulnerabilities impact GitLab Community Edition (CE) and Enterprise Edition (EE) versions prior to 19.2.5, 19.3.1, and any version before 19.1.7. The CERT-FR has released a security bulletin detailing the affected versions and providing links to patches. The identified vulnerabilities include CVE-2025-10903, CVE-2026-15387, CVE-2026-18252, CVE-2026-3035, CVE-2026-4398, and CVE-2026-7487. Users are advised to consult the GitLab security bulletin for detailed information and to apply the necessary patches promptly.

Read the full article at CERT-FR