VDB

GCVE-110-NCSC-2026-196

GCVE-110-NCSC-2026-196
Advisory PublishedCVSS 8.7/10
Vulnetix · Advisory published June 12, 2026
GitLab addressed a security vulnerability in versions 12.0 to before 18.10.8, 18.11 to before 18.11.5, and 19.0 to before 19.0.2 that allowed authenticated users to improperly access confidential issue details due to authorization flaws.

Weaknesses (CWE)

CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-1021Improper Restriction of Rendered UI Layers or FramesCWE-770Allocation of Resources Without Limits or ThrottlingCWE-863Incorrect AuthorizationCWE-639Authorization Bypass Through User-Controlled KeyCWE-918Server-Side Request Forgery (SSRF)CWE-153Improper Neutralization of Substitution Characters

Risk Scores

CVSS 3.1
8.7/10
High · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Affected Products

VendorProductVersionsPlatforms
GitLabvers:unknown/*
Open Sourcevers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,366 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›