GitLab
GitLab Patch Release: 18.11.3, 18.10.6, 18.9.7
patch-release-gitlab-18-11-3-released May 13, 2026 Source: Vendor
Imported by the GitLab patch release catcher from https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-11-3-released/. 25 CVE sections listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-11-3-released/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
21 lines
Showing 1–21 of 21
CVE-2026-7481
BR2026-0000-008809
unclaimed
Cross-site Scripting issue in Analytics dashboard chart rendering impacts GitLab EE
Credited as yvvdwf
CVE-2026-6073
BR2026-0000-008810
unclaimed
Cross-site Scripting issue in Duo Agent output rendering impacts GitLab EE
Credited as joaxcar
CVE-2026-7377
BR2026-0000-008811
unclaimed
Cross-site Scripting issue in Analytics Dashboard impacts GitLab EE
Credited as aphantom
CVE-2026-1659
BR2026-0000-008812
unclaimed
Denial of Service issue in CI/CD job update API impacts GitLab CE/EE
Credited as a92847865
CVE-2025-14870
BR2026-0000-008813
unclaimed
Denial of Service issue in Duo Workflows API impacts GitLab CE/EE
Credited as a92847865
CVE-2025-14869
BR2026-0000-008814
unclaimed
Denial of Service issue in internal API endpoints impacts GitLab CE/EE
Credited as a92847865
CVE-2026-1322
BR2026-0000-008815
unclaimed
Improper Authorization issue in GraphQL token scope enforcement impacts GitLab CE/EE
Credited as mateuszek
CVE-2026-1184
BR2026-0000-008816
unclaimed
Denial of Service issue in Insights Configuration impacts GitLab EE
Credited as a92847865
CVE-2026-4524
BR2026-0000-008817
unclaimed
Access Control issue in Issues API impacts GitLab CE/EE
Credited as hackaccinocraft
CVE-2026-8280
BR2026-0000-008818
unclaimed
Denial of Service issue in direct transfer CSV parser impacts GitLab CE/EE
Credited as a92847865
CVE-2026-4527
BR2026-0000-008819
unclaimed
CSRF issue in JiraConnect subscriptions impacts GitLab CE/EE
Credited as maksyche
CVE-2026-3160
BR2026-0000-008820
unclaimed
Confused Deputy issue in Jira integration impacts GitLab CE/EE
Credited as maksyche
CVE-2026-6335
BR2026-0000-008821
unclaimed
Cross-site Scripting issue in Banzai markdown sanitizer impacts GitLab CE/EE
Credited as toofikz
CVE-2025-12669
BR2026-0000-008822
unclaimed
Cross-site Scripting issue in achievement email notifications impacts GitLab CE/EE
Credited as ricardobrito
CVE-2026-3607
BR2026-0000-008823
unclaimed
Access Control issue in Helm package upload impacts GitLab CE/EE
Credited as aphantom
CVE-2026-3074
BR2026-0000-008824
unclaimed
Improper Access Control issue in NuGet Symbol Server impacts GitLab CE/EE
Credited as sndd
CVE-2026-1338
BR2026-0000-008825
unclaimed
Improper Access Control issue in Container Registry protected tags impacts GitLab CE/EE
Credited as go7f0
CVE-2026-6063
BR2026-0000-008826
unclaimed
Improper Access Control issue in code owner approval rules impacts GitLab EE
Credited as pollito
CVE-2026-3073
BR2026-0000-008827
unclaimed
Access Control issue in PyPI Package Protection Rules impacts GitLab CE/EE
Credited as modhanami
CVE-2025-13874
BR2026-0000-008828
unclaimed
Improper Access Control issue in issue links API impacts GitLab CE/EE
Credited as go7f0
CVE-2026-2900
BR2026-0000-008829
unclaimed
Access Control issue in GraphQL approval rule mutations impacts GitLab EE
Credited as modhanami