FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Gitlab -- vulnerabilities

Affected packages
18.11.0 <= gitlab-ce < 18.11.3
18.10.0 <= gitlab-ce < 18.10.6
8.3.0 <= gitlab-ce < 18.9.7
18.11.0 <= gitlab-ee < 18.11.3
18.10.0 <= gitlab-ee < 18.10.6
8.3.0 <= gitlab-ee < 18.9.7

Details

VuXML ID b3cb8f40-4f4c-11f1-80f1-2cf05da270f3
Discovery 2026-05-13
Entry 2026-05-14

Gitlab reports:

Cross-site Scripting issue in Analytics dashboard chart rendering impacts GitLab EE

Cross-site Scripting issue in global search impacts GitLab CE/EE

Cross-site Scripting issue in Duo Agent output rendering impacts GitLab EE

Cross-site Scripting issue in Analytics Dashboard impacts GitLab EE

Denial of Service issue in CI/CD job update API impacts GitLab CE/EE

Denial of Service issue in Duo Workflows API impacts GitLab CE/EE

Denial of Service issue in internal API endpoints impacts GitLab CE/EE

Improper Authorization issue in GraphQL token scope enforcement impacts GitLab CE/EE

Denial of Service issue in Insights Configuration impacts GitLab EE

Access Control issue in Issues API impacts GitLab CE/EE

Denial of Service issue in direct transfer CSV parser impacts GitLab CE/EE

CSRF issue in JiraConnect subscriptions impacts GitLab CE/EE

Confused Deputy issue in Jira integration impacts GitLab CE/EE

Cross-site Scripting issue in Banzai markdown sanitizer impacts GitLab CE/EE

Cross-site Scripting issue in achievement email notifications impacts GitLab CE/EE

Access Control issue in Helm package upload impacts GitLab CE/EE

Improper Access Control issue in NuGet Symbol Server impacts GitLab CE/EE

Improper Access Control issue in Container Registry protected tags impacts GitLab CE/EE

Missing Authorization issue in group user search impacts GitLab CE/EE

Improper Access Control issue in code owner approval rules impacts GitLab EE

Access Control issue in PyPI Package Protection Rules impacts GitLab CE/EE

Improper Access Control issue in issue links API impacts GitLab CE/EE

Server-Side Request Forgery issue in virtual registry redirect handler impacts GitLab EE

Access Control issue in GraphQL approval rule mutations impacts GitLab EE

Missing Authorization issue in Security Policy Project Reassignment impacts GitLab EE

References

CVE Name CVE-2025-12669
CVE Name CVE-2025-13874
CVE Name CVE-2025-14869
CVE Name CVE-2025-14870
CVE Name CVE-2026-1184
CVE Name CVE-2026-1322
CVE Name CVE-2026-1338
CVE Name CVE-2026-1659
CVE Name CVE-2026-2900
CVE Name CVE-2026-3073
CVE Name CVE-2026-3074
CVE Name CVE-2026-3160
CVE Name CVE-2026-3607
CVE Name CVE-2026-4524
CVE Name CVE-2026-4527
CVE Name CVE-2026-5297
CVE Name CVE-2026-6063
CVE Name CVE-2026-6073
CVE Name CVE-2026-6335
CVE Name CVE-2026-6883
CVE Name CVE-2026-7377
CVE Name CVE-2026-7471
CVE Name CVE-2026-7481
CVE Name CVE-2026-8144
CVE Name CVE-2026-8280
URL https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-11-3-released/