Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

GitLab

GitLab Patch Release: 18.9.2, 18.8.6, 18.7.6

patch-release-gitlab-18-9-2-released Mar 11, 2026 Source: Vendor

Imported by the GitLab patch release catcher from https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-9-2-released/. 15 CVE sections listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-9-2-released/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

15 lines
Showing 1–15 of 15
CVE-2026-1090 BR2026-0000-009244 unclaimed
Cross-site Scripting issue in Markdown placeholder processing impacts GitLab CE/EE
Credited as yvvdwf
CVE-2026-1069 BR2026-0000-009245 unclaimed
Denial of Service issue in GraphQL API impacts GitLab CE/EE
Credited as a92847865
CVE-2025-13929 BR2026-0000-009246 unclaimed
Denial of Service issue in repository archive endpoint impacts GitLab CE/EE
Credited as joaxcar
CVE-2025-14513 BR2026-0000-009247 unclaimed
Denial of Service issue in protected branches API impacts GitLab CE/EE
Credited as a92847865
CVE-2025-13690 BR2026-0000-009248 unclaimed
Denial of Service issue in webhook custom headers impacts GitLab CE/EE
Credited as sim4n6
CVE-2025-12576 BR2026-0000-009249 unclaimed
Denial of Service issue in webhook endpoint impacts GitLab CE/EE
Credited as sim4n6
CVE-2026-3848 BR2026-0000-009250 unclaimed
Improper Neutralization of CRLF Sequences issue impacts GitLab CE/EE
Credited as shells3c
CVE-2025-12555 BR2026-0000-009251 unclaimed
Improper Access Control issue in runners API impacts GitLab CE/EE
Credited as iamgk808
CVE-2026-0602 BR2026-0000-009252 unclaimed
Improper Access Control issue in snippet rendering impacts GitLab CE/EE
Credited as go7f0
CVE-2026-1732 BR2026-0000-009253 unclaimed
Information Disclosure issue in inaccessible issues impacts GitLab CE/EE
Credited as modhanami
CVE-2026-1663 BR2026-0000-009254 unclaimed
Missing Authorization issue in Group Import impacts GitLab CE/EE
Credited as go7f0
CVE-2026-1230 BR2026-0000-009255 unclaimed
Incorrect Reference issue in repository download impacts GitLab CE/EE
Credited as st4nly0n
CVE-2026-1182 BR2026-0000-009256 unclaimed
Information Disclosure issue in confidential issues impacts GitLab CE/EE
Credited as yvvdwf
CVE-2025-12704 BR2026-0000-009257 unclaimed
Incorrect Authorization issue in Virtual Registry impacts GitLab EE
Credited as mateuszek
CVE-2025-12697 BR2026-0000-009258 unclaimed
Improper Escaping of Output issue in Datadog integration impacts GitLab CE/EE
Credited as shells3c