GitLab patches 13 flaws including SSRF and XSS
GitLab released patches for 13 vulnerabilities across CE and EE versions 18.11.x through 19.1.x, including SSRF, XSS, and confidentiality issues.
The French CERT (CERT-FR) issued an advisory regarding multiple vulnerabilities discovered in GitLab Community Edition (CE) and Enterprise Edition (EE). The affected versions include 19.0.x prior to 19.0.3, 19.1.x prior to 19.1.1, and all versions prior to 18.11.6. The vulnerabilities enable various attack vectors including data confidentiality breaches, server-side request forgery (SSRF), cross-site scripting (XSS), and security policy bypass.
GitLab released patches on June 24, 2026 addressing thirteen distinct CVEs. The advisory identifies specific risks including unauthorized access to sensitive data, the ability to forge requests from the server side, and remote code injection through XSS vulnerabilities. Organizations running affected GitLab versions should prioritize patching to mitigate these risks.
The CERT-FR advisory recommends immediate consultation of GitLab's security bulletin for obtaining and applying the necessary patches. Given GitLab's widespread use in software development environments, these vulnerabilities represent a significant exposure for organizations hosting their own GitLab instances.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0799
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free