CVE-2026-10053

2 karet z 3 položek · v celém archivu · celý přehled CZ · EN/orig

CVE-2026-10053

EPSS 0.01

Hodnocení závažnosti

8.5 CVSS 3.1 GitLab

útok odkudkoli z internetu útok vyžaduje přípravu stačí běžný účet bez zásahu uživatele
dopad plný únik dat úplná změna dat úplný výpadek
přesah dopad i mimo zranitelnou součást

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

zvyšuje závažnost mírně zvyšuje závažnost snižuje závažnost

1

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.5, CVEs: CVE-2026-10053, Summary: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.

EPSS 0.01 CVSS 8.5 CVE-2026-10053 GitLab FI

NCSC-FI ·

1

GitLab Patch Release: 19.2.2, 19.1.4, 19.0.6

On August 12, 2026, we released versions 19.2.2, 19.1.4, 19.0.6 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of patch…

EPSS 0.01 CVSS 8.7 CVE-2026-10053 CVE-2026-15216 CVE-2026-15217 CVE-2026-15423 CVE-2026-16494 CVE-2026-16627 CVE-2026-19228 CVE-2026-6821 CVE-2026-7427 GitLab US

GitLab Security ·