GitLab
GitLab Patch Release: 18.10.1, 18.9.3, 18.8.7
patch-release-gitlab-18-10-1-released Mar 25, 2026 Source: Vendor
Imported by the GitLab patch release catcher from https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-10-1-released/. 12 CVE sections listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-10-1-released/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
12 lines
Showing 1–12 of 12
CVE-2026-2370
BR2026-0000-008872
unclaimed
Improper Handling of Parameters issue in Jira Connect installations impacts GitLab CE/EE
Credited as maksyche
CVE-2026-3857
BR2026-0000-008873
unclaimed
Cross-Site Request Forgery issue in GLQL API impacts GitLab CE/EE
Credited as ahacker1
CVE-2026-2995
BR2026-0000-008874
unclaimed
HTML Injection in vulnerability report impacts GitLab EE
Credited as a_m_a_m
CVE-2026-2995
BR2026-0000-008875
unclaimed
HTML Injection in vulnerability report impacts GitLab EE
Credited as yvvdwf
CVE-2026-3988
BR2026-0000-008876
unclaimed
Denial of Service issue in GraphQL API impacts GitLab CE/EE
Credited as svalkanov
CVE-2026-2745
BR2026-0000-008877
unclaimed
Improper Access Control issue in WebAuthn 2FA impacts GitLab CE/EE
Credited as a0xnirudh
CVE-2026-1724
BR2026-0000-008878
unclaimed
Improper Access Control issue in GraphQL query impacts GitLab EE
Credited as maksyche
CVE-2025-13436
BR2026-0000-008879
unclaimed
Denial of Service issue in CI configuration processing impacts GitLab CE/EE
Credited as a92847865
CVE-2025-13078
BR2026-0000-008880
unclaimed
Denial of Service issue in webhook configuration impacts GitLab CE/EE
Credited as lucky_luke
CVE-2026-2973
BR2026-0000-008881
unclaimed
Cross-site Scripting issue in Mermaid diagram renderer impacts GitLab CE/EE
Credited as go7f0
CVE-2026-2726
BR2026-0000-008882
unclaimed
Improper Access Control issue in Merge Requests impacts GitLab CE/EE
Credited as pkkr
CVE-2025-14595
BR2026-0000-008883
unclaimed
Access Control issue in GraphQL API impacts GitLab EE
Credited as kamikaze1337