- Description
- GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control.
- Source
- cve@gitlab.com
- NVD status
- Analyzed
- Products
- gitlab
CVSS 3.1
- Type
- Secondary
- Base score
- 8.5
- Impact score
- 4.7
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
- Severity
- HIGH
- cve@gitlab.com
- CWE-749
- Hype score
- Not currently trending
⚠️ Vulnerabilidades en productos GitLab ❗ CVE-2026-5173 ❗ CVE-2026-1092 ❗ CVE-2025-12664 ➡️ Más info: https://t.co/3GU5SIpUvx https://t.co/D1iCzaS7Aq
@CERTpy
16 Apr 2026
107 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-5173, CVE-2026-1092, CVE-2025-12664 and other: Vulnerabilities in GitLab CE and EE, up to 8.5 rating 🔥 Several vulnerabilities in GitLab could compromise code integrity and allow an unauthenticated user to cause denial of service. 👉https://t.co/Zbj1GEqSyV https:/
@Netlas_io
11 Apr 2026
500 Impressions
2 Retweets
3 Likes
5 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "4C2970CC-B6D7-43CB-9E8C-D7F50DD13BD6",
"versionEndExcluding": "18.8.9",
"versionStartIncluding": "16.9.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "3BA6A89D-D2C1-45B9-A8E8-64256816D880",
"versionEndExcluding": "18.9.5",
"versionStartIncluding": "18.9.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "BB2F3665-2451-4A4D-8538-93F540975F0E",
"versionEndExcluding": "18.10.3",
"versionStartIncluding": "18.10.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"matchCriteriaId": "50442516-A352-4018-AC06-22242834A510",
"versionEndExcluding": "18.8.9",
"versionStartIncluding": "16.9.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"matchCriteriaId": "5C4D8A99-6E70-4D55-9ACF-FF2620F070E0",
"versionEndExcluding": "18.9.5",
"versionStartIncluding": "18.9.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"matchCriteriaId": "DBCB346F-0B28-458B-A453-29DA4B0E91FC",
"versionEndExcluding": "18.10.3",
"versionStartIncluding": "18.10.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]