VDB
CVE-2026-12053
CVE-2026-12053
PUBLISHED
CVSS 8.6 HIGH
Reported by GitLab · Published June 25, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows.
Risk Scores
CVSS 3.1
8.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| GitLab | GitLab | 19.1 |
| GitLab | GitLab | 19.1 |
Timeline
- Jun 25, 2026 EPSS Score
- Jun 25, 2026 Coalition ESS Score
- Jun 25, 2026 CVE Published
- Jun 29, 2026 Security Advisory
References
- HackerOne Bug Bounty Report #3757762 technical-descriptionexploitpermissions-required