FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Gitlab -- vulnerabilities

Affected packages
18.11.0 <= gitlab-ce < 18.11.1
18.10.0 <= gitlab-ce < 18.10.4
9.2.0 <= gitlab-ce < 18.9.6
18.11.0 <= gitlab-ee < 18.11.1
18.10.0 <= gitlab-ee < 18.10.4
9.2.0 <= gitlab-ee < 18.9.6

Details

VuXML ID 73b927a6-3ecd-11f1-be20-2cf05da270f3
Discovery 2026-04-22
Entry 2026-04-23

Gitlab reports:

Cross-Site Request Forgery issue in GraphQL API impacts GitLab CE/EE GitLab

Improper Resolution of Path Equivalence issue in Web IDE asset impacts GitLab CE/EE

Cross-site Scripting issue in Storybook impacts GitLab CE/EE

Denial of Service issue in discussions endpoint impacts GitLab CE/EE

Denial of Service issue in Jira import impacts GitLab CE/EE

Denial of Service issue in notes endpoint impacts GitLab CE/EE

Denial of Service issue in GraphQL API impacts GitLab CE/EE

Insufficient Session Expiration issue in virtual registry credentials validation impacts GitLab CE/E

Improper Access Control issue in issue description renderer impacts GitLab CE/EE

Improper Restriction of Rendered UI Layers or Frames issue in Mermaid sandbox impacts GitLab CE/EE

Improper Access Control issue in project fork relationship API impacts GitLab CE/EE

References

CVE Name CVE-2025-0186
CVE Name CVE-2025-3922
CVE Name CVE-2025-6016
CVE Name CVE-2025-9957
CVE Name CVE-2026-1660
CVE Name CVE-2026-3254
CVE Name CVE-2026-4922
CVE Name CVE-2026-5262
CVE Name CVE-2026-5377
CVE Name CVE-2026-5816
CVE Name CVE-2026-6515
URL https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-11-1-released/