GitLab Community Edition (CE) and Enterprise Edition (EE) are vulnerable. Those who host GitLab instances themselves should quickly install the available security patches. Repaired versions are reportedly already running on Gitlab.com.
In a warning message , the developers list the secured versions 18.10.1, 18.9.3, and 18.8.7 . Younger versions are susceptible to attacks, and attackers can exploit twelve vulnerabilities. Four of these are classified as " high " threat level (CVE-2026-2370, CVE-2026-3857, CVE-2026-2995, CVE-2026-3988).
If attackers successfully exploit these vulnerabilities, they can, among other things, trigger DoS states or add email addresses to existing user accounts. The remaining gaps weaken authentication, among other things (e.g., CVE-2026-2726 " medium ").
The software manufacturer advises a swift update. So far, there are no reports that attackers are already exploiting the vulnerabilities.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
