GitLab
GitLab Patch Release: 18.8.4, 18.7.4, 18.6.6
patch-release-gitlab-18-8-4-released Feb 10, 2026 Source: Vendor
Imported by the GitLab patch release catcher from https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-8-4-released/. 15 CVE sections listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-8-4-released/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
17 lines
Showing 1–17 of 17
CVE-2025-7659
BR2026-0000-009267
unclaimed
Incomplete Validation issue in Web IDE impacts GitLab CE/EE
Credited as cav0ur
CVE-2025-8099
BR2026-0000-009268
unclaimed
Denial of Service issue in GraphQL introspection impacts GitLab CE/EE
Credited as foxribeye
CVE-2026-0958
BR2026-0000-009269
unclaimed
Denial of Service issue in JSON validation middleware impacts GitLab CE/EE
Credited as elbo7
CVE-2025-14560
BR2026-0000-009270
unclaimed
Cross-site Scripting issue in Code Flow impacts GitLab CE/EE
Credited as joaxcar
CVE-2025-14560
BR2026-0000-009271
unclaimed
Cross-site Scripting issue in Code Flow impacts GitLab CE/EE
Credited as yvvdwf
CVE-2026-0595
BR2026-0000-009272
unclaimed
HTML Injection issue in test case titles impacts GitLab CE/EE
Credited as yvvdwf
CVE-2026-0595
BR2026-0000-009273
unclaimed
HTML Injection issue in test case titles impacts GitLab CE/EE
Credited as joaxcar
CVE-2026-1458
BR2026-0000-009274
unclaimed
Denial of Service issue in Markdown processor impacts GitLab CE/EE
Credited as maksyche
CVE-2026-1456
BR2026-0000-009275
unclaimed
Denial of Service issue in Markdown Preview impacts GitLab CE/EE
Credited as maksyche
CVE-2026-1387
BR2026-0000-009276
unclaimed
Denial of Service issue in dashboard impacts GitLab EE
Credited as a92847865
CVE-2025-12575
BR2026-0000-009277
unclaimed
Server-Side Request Forgery issue in Virtual Registry impacts GitLab EE
Credited as go7f0qho
CVE-2026-1094
BR2026-0000-009278
unclaimed
Improper Validation issue in diff parser impacts GitLab CE/EE
Credited as u3mur4
CVE-2025-12073
BR2026-0000-009279
unclaimed
Server-Side Request Forgery issue in Git repository import impacts GitLab CE/EE
Credited as yunus0x
CVE-2026-1080
BR2026-0000-009280
unclaimed
Authorization Bypass issue in iterations API impacts GitLab EE
Credited as go7f0
CVE-2025-14592
BR2026-0000-009281
unclaimed
Missing Authorization issue in GLQL API impacts GitLab CE/EE
Credited as go7f0
CVE-2026-1282
BR2026-0000-009282
unclaimed
Stored HTML Injection issue in project label impacts GitLab CE/EE
Credited as rafabd1
CVE-2025-14594
BR2026-0000-009283
unclaimed
Authorization Bypass issue in Pipeline Schedules API impacts GitLab CE/EE
Credited as sndd