VDB
GCVE-110-NCSC-2026-196
GCVE-110-NCSC-2026-196
Advisory PublishedCVSS 8.7/10
GitLab addressed a security vulnerability in versions 12.0 to before 18.10.8, 18.11 to before 18.11.5, and 19.0 to before 19.0.2 that allowed authenticated users to improperly access confidential issue details due to authorization flaws.
Weaknesses (CWE)
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-1021Improper Restriction of Rendered UI Layers or FramesCWE-770Allocation of Resources Without Limits or ThrottlingCWE-863Incorrect AuthorizationCWE-639Authorization Bypass Through User-Controlled KeyCWE-918Server-Side Request Forgery (SSRF)CWE-153Improper Neutralization of Substitution Characters
Risk Scores
CVSS 3.1
8.7/10
High · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GitLab | vers:unknown/* | — | — |
| Open Source | vers:unknown/* | — | — |
Browse GCVE Records
74,366 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.