VDB

GCVE-110-NCSC-2026-161

GCVE-110-NCSC-2026-161
Advisory PublishedCVSS 5.8/10
Vulnetix · Advisory published May 15, 2026
GitLab addressed a security vulnerability in versions 18.3 to before 18.9.7, 18.10 to before 18.10.6, and 18.11 to before 18.11.3 that allowed authenticated users with developer roles to bypass package protection rules due to improper access control.

Weaknesses (CWE)

CWE-441Unintended Proxy or Intermediary ('Confused Deputy')CWE-352Cross-Site Request Forgery (CSRF)CWE-770Allocation of Resources Without Limits or ThrottlingCWE-639Authorization Bypass Through User-Controlled KeyCWE-918Server-Side Request Forgery (SSRF)CWE-862Missing AuthorizationCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-288Authentication Bypass Using an Alternate Path or ChannelCWE-502Deserialization of Untrusted DataCWE-94Improper Control of Generation of Code ('Code Injection')CWE-1280Access Control Check Implemented After Asset is AccessedCWE-1284Improper Validation of Specified Quantity in Input

Risk Scores

CVSS 3.1
5.8/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Affected Products

VendorProductVersionsPlatforms
GitLabvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

73,866 records in the GCVE database · Updated July 19, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›