GitLab
GitLab Patch Release: 18.10.3, 18.9.5, 18.8.9
patch-release-gitlab-18-10-3-released Apr 8, 2026 Source: Vendor
Imported by the GitLab patch release catcher from https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-10-3-released/. 12 CVE sections listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-10-3-released/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
11 lines
Showing 1–11 of 11
CVE-2026-1092
BR2026-0000-008861
unclaimed
Denial of Service issue in Terraform state lock API impacts GitLab CE/EE
Credited as a92847865
CVE-2025-12664
BR2026-0000-008862
unclaimed
Denial of Service issue in GraphQL API impacts GitLab CE/EE
Credited as foxribeye
CVE-2026-1403
BR2026-0000-008863
unclaimed
Denial of Service issue in CSV import impacts GitLab CE/EE
Credited as a92847865
CVE-2026-1101
BR2026-0000-008864
unclaimed
Denial of Service issue in GraphQL SBOM API impacts GitLab EE
Credited as sim4n6
CVE-2026-1516
BR2026-0000-008865
unclaimed
Code Injection issue in Code Quality reports impacts GitLab EE
Credited as maksyche
CVE-2026-4332
BR2026-0000-008866
unclaimed
Cross-site Scripting issue in analytics dashboards impacts GitLab EE
Credited as go7f0
CVE-2026-2619
BR2026-0000-008867
unclaimed
Incorrect Authorization issue in vulnerability flags AI detection API impacts GitLab EE
Credited as sage_cyberlord
CVE-2025-9484
BR2026-0000-008868
unclaimed
Information Disclosure issue in certain GraphQl query impacts GitLab EE
Credited as mateuszek
CVE-2026-1752
BR2026-0000-008869
unclaimed
Improper Access Control issue in Environments API impacts GitLab EE
Credited as modhanami
CVE-2026-2104
BR2026-0000-008870
unclaimed
Information Disclosure issue in CSV export impacts GitLab CE/EE
Credited as ahacker1
CVE-2026-4916
BR2026-0000-008871
unclaimed
Missing Authorization issue in custom role permissions impacts GitLab CE/EE
Credited as theluci