Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

GitLab

GitLab Patch Release: 18.11.3, 18.10.6, 18.9.7

patch-release-gitlab-18-11-3-released May 13, 2026 Source: Vendor

Imported by the GitLab patch release catcher from https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-11-3-released/. 25 CVE sections listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-11-3-released/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

21 lines
Showing 1–21 of 21
CVE-2026-7481 BR2026-0000-008809 unclaimed
Cross-site Scripting issue in Analytics dashboard chart rendering impacts GitLab EE
Credited as yvvdwf
CVE-2026-6073 BR2026-0000-008810 unclaimed
Cross-site Scripting issue in Duo Agent output rendering impacts GitLab EE
Credited as joaxcar
CVE-2026-7377 BR2026-0000-008811 unclaimed
Cross-site Scripting issue in Analytics Dashboard impacts GitLab EE
Credited as aphantom
CVE-2026-1659 BR2026-0000-008812 unclaimed
Denial of Service issue in CI/CD job update API impacts GitLab CE/EE
Credited as a92847865
CVE-2025-14870 BR2026-0000-008813 unclaimed
Denial of Service issue in Duo Workflows API impacts GitLab CE/EE
Credited as a92847865
CVE-2025-14869 BR2026-0000-008814 unclaimed
Denial of Service issue in internal API endpoints impacts GitLab CE/EE
Credited as a92847865
CVE-2026-1322 BR2026-0000-008815 unclaimed
Improper Authorization issue in GraphQL token scope enforcement impacts GitLab CE/EE
Credited as mateuszek
CVE-2026-1184 BR2026-0000-008816 unclaimed
Denial of Service issue in Insights Configuration impacts GitLab EE
Credited as a92847865
CVE-2026-4524 BR2026-0000-008817 unclaimed
Access Control issue in Issues API impacts GitLab CE/EE
Credited as hackaccinocraft
CVE-2026-8280 BR2026-0000-008818 unclaimed
Denial of Service issue in direct transfer CSV parser impacts GitLab CE/EE
Credited as a92847865
CVE-2026-4527 BR2026-0000-008819 unclaimed
CSRF issue in JiraConnect subscriptions impacts GitLab CE/EE
Credited as maksyche
CVE-2026-3160 BR2026-0000-008820 unclaimed
Confused Deputy issue in Jira integration impacts GitLab CE/EE
Credited as maksyche
CVE-2026-6335 BR2026-0000-008821 unclaimed
Cross-site Scripting issue in Banzai markdown sanitizer impacts GitLab CE/EE
Credited as toofikz
CVE-2025-12669 BR2026-0000-008822 unclaimed
Cross-site Scripting issue in achievement email notifications impacts GitLab CE/EE
Credited as ricardobrito
CVE-2026-3607 BR2026-0000-008823 unclaimed
Access Control issue in Helm package upload impacts GitLab CE/EE
Credited as aphantom
CVE-2026-3074 BR2026-0000-008824 unclaimed
Improper Access Control issue in NuGet Symbol Server impacts GitLab CE/EE
Credited as sndd
CVE-2026-1338 BR2026-0000-008825 unclaimed
Improper Access Control issue in Container Registry protected tags impacts GitLab CE/EE
Credited as go7f0
CVE-2026-6063 BR2026-0000-008826 unclaimed
Improper Access Control issue in code owner approval rules impacts GitLab EE
Credited as pollito
CVE-2026-3073 BR2026-0000-008827 unclaimed
Access Control issue in PyPI Package Protection Rules impacts GitLab CE/EE
Credited as modhanami
CVE-2025-13874 BR2026-0000-008828 unclaimed
Improper Access Control issue in issue links API impacts GitLab CE/EE
Credited as go7f0
CVE-2026-2900 BR2026-0000-008829 unclaimed
Access Control issue in GraphQL approval rule mutations impacts GitLab EE
Credited as modhanami