Changeflow GovPing Data Privacy & Cybersecurity GitLab Vulnerabilities Pose Data Integrity and ...
Priority review Notice Added Final

GitLab Vulnerabilities Pose Data Integrity and XSS Risks

Favicon for www.cert.ssi.gouv.fr CERT-FR Security Advisories
Published March 25th, 2026
Detected March 25th, 2026
Email

Summary

CERT-FR has issued a security advisory regarding multiple vulnerabilities discovered in GitLab Community and Enterprise Editions. These vulnerabilities could allow attackers to compromise data integrity, execute cross-site scripting (XSS) attacks, and cause remote denial of service.

What changed

CERT-FR, the French national cybersecurity agency, has issued an advisory (CERTFR-2026-AVI-0357) detailing multiple critical vulnerabilities found in various versions of GitLab Community Edition (CE) and Enterprise Edition (EE). The identified risks include data integrity compromise, security policy bypass, remote denial of service, indirect remote code injection (XSS), and cross-site request forgery (CSRF). Specific affected versions include those prior to 18.10.1 for 18.10.x, prior to 18.9.3 for 18.9.x, and prior to 18.8.7 for older versions.

Organizations utilizing affected GitLab instances must immediately consult the vendor's security bulletin and apply the provided patches to mitigate these risks. Failure to do so could expose systems to significant security breaches, including data corruption and unauthorized code execution. The advisory references numerous CVEs, underscoring the severity and breadth of the discovered vulnerabilities.

What to do next

  1. Consult GitLab's security bulletin for patch information
  2. Apply available patches to affected GitLab versions
  3. Review system logs for signs of compromise

Source document (simplified)

Premier Ministre S.G.D.S.N

Agence nationale
de la sécurité des
systèmes d'information

Paris, le 25 mars 2026 N° CERTFR-2026-AVI-0357 Affaire suivie par: CERT-FR

Avis du CERT-FR

Objet: Multiples vulnérabilités dans GitLab

Gestion du document

| Référence | CERTFR-2026-AVI-0357 |
| Titre | Multiples vulnérabilités dans GitLab |
| Date de la première version | 25 mars 2026 |
| Date de la dernière version | 25 mars 2026 |
| Source(s) | Bulletin de sécurité GitLab du 25 mars 2026 |
Une gestion de version détaillée se trouve à la fin de ce document.


Risques

  • Atteinte à l'intégrité des données
  • Contournement de la politique de sécurité
  • Déni de service à distance
  • Injection de code indirecte à distance (XSS)
  • Injection de requêtes illégitimes par rebond (CSRF)

Systèmes affectés

  • GitLab Community Edition (CE) et Gitlab Enterprise Edition (EE) versions 18.10.x antérieures à 18.10.1
  • GitLab Community Edition (CE) et Gitlab Enterprise Edition (EE) versions 18.9.x antérieures à 18.9.3
  • GitLab Community Edition (CE) et Gitlab Enterprise Edition (EE) versions antérieures à 18.8.7

Résumé

De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à l'intégrité des données et une injection de code indirecte à distance (XSS).

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Documentation


Gestion détaillée du document

  1. le 25 mars 2026 Version initiale

Named provisions

Risks Affected Systems Summary Solutions Documentation

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-FR
Published
March 25th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
CERTFR-2026-AVI-0357

Who this affects

Applies to
Technology companies
Industry sector
5112 Software & Technology
Activity scope
Software Development Source Code Management
Geographic scope
France FR

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Data Integrity Cross-Site Scripting (XSS) Denial of Service

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-FR Security Advisories publishes new changes.

Free. Unsubscribe anytime.