- What: Multiple vulnerabilities have been identified in GitLab that could lead to denial of service, cross-site scripting, data manipulation, information disclosure, and security restriction bypass.
- Impact: GitLab Community Edition (CE) and Enterprise Edition (EE) versions prior to 18.8.4, 18.7.4, 18.6.6 are affected.
- Patch: Apply the fixes issued by the vendor.
Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, cross-site scripting, data manipulation, information disclosure and security restriction bypass on the targeted system. Impact Denial of Service Security Restriction Bypass Cross-Site Scripting Data Manipulation Information Disclosure System / Technologies affected GitLab Community Edition (CE) versions prior to 18.8.4, 18.7.4, 18.6.6 GitLab Enterprise Edition (EE) versions prior to 18.8.4, 18.7.4, 18.6.6 Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/