VDB
GCVE-110-NCSC-2026-161
GCVE-110-NCSC-2026-161
Advisory PublishedCVSS 5.8/10
GitLab addressed a security vulnerability in versions 18.3 to before 18.9.7, 18.10 to before 18.10.6, and 18.11 to before 18.11.3 that allowed authenticated users with developer roles to bypass package protection rules due to improper access control.
Weaknesses (CWE)
CWE-441Unintended Proxy or Intermediary ('Confused Deputy')CWE-352Cross-Site Request Forgery (CSRF)CWE-770Allocation of Resources Without Limits or ThrottlingCWE-639Authorization Bypass Through User-Controlled KeyCWE-918Server-Side Request Forgery (SSRF)CWE-862Missing AuthorizationCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-288Authentication Bypass Using an Alternate Path or ChannelCWE-502Deserialization of Untrusted DataCWE-94Improper Control of Generation of Code ('Code Injection')CWE-1280Access Control Check Implemented After Asset is AccessedCWE-1284Improper Validation of Specified Quantity in Input
Risk Scores
CVSS 3.1
5.8/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GitLab | vers:unknown/* | — | — |
Aliases
CVE-2025-12669CVE-2025-13874CVE-2025-14869CVE-2025-14870CVE-2026-1184CVE-2026-1322CVE-2026-1338CVE-2026-1659CVE-2026-2900CVE-2026-3073CVE-2026-3074CVE-2026-3160CVE-2026-3607CVE-2026-4524CVE-2026-4527CVE-2026-5297CVE-2026-6063CVE-2026-6073CVE-2026-6335CVE-2026-6883CVE-2026-7377CVE-2026-7471CVE-2026-7481CVE-2026-8144CVE-2026-8280
Browse GCVE Records
73,866 records in the GCVE database · Updated July 19, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.