Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

GitLab

GitLab Patch Release: 18.10.1, 18.9.3, 18.8.7

patch-release-gitlab-18-10-1-released Mar 25, 2026 Source: Vendor

Imported by the GitLab patch release catcher from https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-10-1-released/. 12 CVE sections listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-10-1-released/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

12 lines
Showing 1–12 of 12
CVE-2026-2370 BR2026-0000-008872 unclaimed
Improper Handling of Parameters issue in Jira Connect installations impacts GitLab CE/EE
Credited as maksyche
CVE-2026-3857 BR2026-0000-008873 unclaimed
Cross-Site Request Forgery issue in GLQL API impacts GitLab CE/EE
Credited as ahacker1
CVE-2026-2995 BR2026-0000-008874 unclaimed
HTML Injection in vulnerability report impacts GitLab EE
Credited as a_m_a_m
CVE-2026-2995 BR2026-0000-008875 unclaimed
HTML Injection in vulnerability report impacts GitLab EE
Credited as yvvdwf
CVE-2026-3988 BR2026-0000-008876 unclaimed
Denial of Service issue in GraphQL API impacts GitLab CE/EE
Credited as svalkanov
CVE-2026-2745 BR2026-0000-008877 unclaimed
Improper Access Control issue in WebAuthn 2FA impacts GitLab CE/EE
Credited as a0xnirudh
CVE-2026-1724 BR2026-0000-008878 unclaimed
Improper Access Control issue in GraphQL query impacts GitLab EE
Credited as maksyche
CVE-2025-13436 BR2026-0000-008879 unclaimed
Denial of Service issue in CI configuration processing impacts GitLab CE/EE
Credited as a92847865
CVE-2025-13078 BR2026-0000-008880 unclaimed
Denial of Service issue in webhook configuration impacts GitLab CE/EE
Credited as lucky_luke
CVE-2026-2973 BR2026-0000-008881 unclaimed
Cross-site Scripting issue in Mermaid diagram renderer impacts GitLab CE/EE
Credited as go7f0
CVE-2026-2726 BR2026-0000-008882 unclaimed
Improper Access Control issue in Merge Requests impacts GitLab CE/EE
Credited as pkkr
CVE-2025-14595 BR2026-0000-008883 unclaimed
Access Control issue in GraphQL API impacts GitLab EE
Credited as kamikaze1337