Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

GitLab

GitLab Patch Release: 18.8.4, 18.7.4, 18.6.6

patch-release-gitlab-18-8-4-released Feb 10, 2026 Source: Vendor

Imported by the GitLab patch release catcher from https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-8-4-released/. 15 CVE sections listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-8-4-released/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

17 lines
Showing 1–17 of 17
CVE-2025-7659 BR2026-0000-009267 unclaimed
Incomplete Validation issue in Web IDE impacts GitLab CE/EE
Credited as cav0ur
CVE-2025-8099 BR2026-0000-009268 unclaimed
Denial of Service issue in GraphQL introspection impacts GitLab CE/EE
Credited as foxribeye
CVE-2026-0958 BR2026-0000-009269 unclaimed
Denial of Service issue in JSON validation middleware impacts GitLab CE/EE
Credited as elbo7
CVE-2025-14560 BR2026-0000-009270 unclaimed
Cross-site Scripting issue in Code Flow impacts GitLab CE/EE
Credited as joaxcar
CVE-2025-14560 BR2026-0000-009271 unclaimed
Cross-site Scripting issue in Code Flow impacts GitLab CE/EE
Credited as yvvdwf
CVE-2026-0595 BR2026-0000-009272 unclaimed
HTML Injection issue in test case titles impacts GitLab CE/EE
Credited as yvvdwf
CVE-2026-0595 BR2026-0000-009273 unclaimed
HTML Injection issue in test case titles impacts GitLab CE/EE
Credited as joaxcar
CVE-2026-1458 BR2026-0000-009274 unclaimed
Denial of Service issue in Markdown processor impacts GitLab CE/EE
Credited as maksyche
CVE-2026-1456 BR2026-0000-009275 unclaimed
Denial of Service issue in Markdown Preview impacts GitLab CE/EE
Credited as maksyche
CVE-2026-1387 BR2026-0000-009276 unclaimed
Denial of Service issue in dashboard impacts GitLab EE
Credited as a92847865
CVE-2025-12575 BR2026-0000-009277 unclaimed
Server-Side Request Forgery issue in Virtual Registry impacts GitLab EE
Credited as go7f0qho
CVE-2026-1094 BR2026-0000-009278 unclaimed
Improper Validation issue in diff parser impacts GitLab CE/EE
Credited as u3mur4
CVE-2025-12073 BR2026-0000-009279 unclaimed
Server-Side Request Forgery issue in Git repository import impacts GitLab CE/EE
Credited as yunus0x
CVE-2026-1080 BR2026-0000-009280 unclaimed
Authorization Bypass issue in iterations API impacts GitLab EE
Credited as go7f0
CVE-2025-14592 BR2026-0000-009281 unclaimed
Missing Authorization issue in GLQL API impacts GitLab CE/EE
Credited as go7f0
CVE-2026-1282 BR2026-0000-009282 unclaimed
Stored HTML Injection issue in project label impacts GitLab CE/EE
Credited as rafabd1
CVE-2025-14594 BR2026-0000-009283 unclaimed
Authorization Bypass issue in Pipeline Schedules API impacts GitLab CE/EE
Credited as sndd