← nejvýznamnější zprávy · všechny zprávy

poslední zpráva

SPOJENO AI EPSS 0.00 (nejvyšší)

GitLab - Multiple Severe Vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.1: 9.9, CVEs: CVE-2026-4523, CVE-2026-8937, CVE-2026-10518, CVE-2026-84739, CVE-2026-89078, CVE-2026-92470, CVE-2026-92529, CVE-2026-92530, CVE-2026-92628, CVE-2026-92874, CVE-2026-93577, Summary: GitLab has fixed multiple vulnerabilities in Community Edition and Enterprise Edition. The most serious vulnerabilities allow authenticated users to execute code by supplying crafted regular expressions through CI/CD…

Číst originál na NCSC-FI →

5 zpráv z 5 zdrojů · první · zachyceno CZ · EN/orig

GitLab CA FI IT FR US

tg: zranitelnost tg: novinka v produktu

CVE v události 11

CVEhodnoceníKEVEPSS
CVE-2026-10518 – – –
CVE-2026-4523 – – –
CVE-2026-84739 – – –
CVE-2026-89078 9.9 3.1 · GitLab – 0.00
CVE-2026-8937 – – –
CVE-2026-92470 7.7 3.1 · GitLab – 0.00
CVE-2026-92529 4.3 3.1 · GitLab – 0.00
CVE-2026-92530 4.3 3.1 · GitLab – 0.00
CVE-2026-92628 3.1 3.1 · GitLab – 0.00
CVE-2026-92874 5.4 3.1 · GitLab – 0.00
CVE-2026-93577 9.9 3.1 · GitLab – 0.00

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.9.

Jak se o tom psalo 5

  1. · Cyber Centre Kanada CA

    GitLab security advisory (AV26-962)

    Serial number: AV26-962Date: September 25, 2026 As of September 23, 2026, GitLab is affected by vulnerabilities in the following product: GitLab Prior to 19.2.7 Prior to 19.3.3 Prior to 19.4.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. GitLab Critical Patch Release: 19.4.1, 19.3.3, 19.2.7 GitLab release notes | GitLab Docs

  2. · zachyceno · NCSC-FI FI nadpis události

    GitLab - Multiple Severe Vulnerabilities

    Classification: Severe, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.1: 9.9, CVEs: CVE-2026-4523, CVE-2026-8937, CVE-2026-10518, CVE-2026-84739, CVE-2026-89078, CVE-2026-92470, CVE-2026-92529, CVE-2026-92530, CVE-2026-92628, CVE-2026-92874, CVE-2026-93577, Summary: GitLab has fixed multiple vulnerabilities in Community Edition and Enterprise Edition. The most serious vulnerabilities allow authenticated users to execute code by supplying crafted regular expressions through CI/CD…

  3. · CSIRT Itálie (ACN) IT

    Risolte vulnerabilità su GitLab CE/EE

    Rilasciati aggiornamenti di sicurezza che risolvono 7 vulnerabilità, di cui una con gravità “alta” e 2 con gravità “critica”, in GitLab Community Edition (CE) ed Enterprise Edition (EE). Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato di accedere ad informazioni riservate o eseguire codice arbitrario sui sistemi interessati.

  4. · zachyceno · CERT-FR – avis FR

    Multiples vulnérabilités dans GitLab (24 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une atteinte à la confidentialité des données et une injection de code indirecte à distance (XSS).

  5. · zachyceno · GitLab Security US

    GitLab Critical Patch Release: 19.4.1, 19.3.3, 19.2.7

    On September 23, 2026, we released versions 19.4.1, 19.3.3, 19.2.7 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of…