FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Gitlab -- vulnerabilities

Affected packages
19.0.0 <= gitlab-ce < 19.0.2
18.11.0 <= gitlab-ce < 18.11.5
12.0.0 <= gitlab-ce < 18.10.8
19.0.0 <= gitlab-ee < 19.0.2
18.11.0 <= gitlab-ee < 18.11.5
12.0.0 <= gitlab-ee < 18.10.8

Details

VuXML ID ac9bab80-6618-11f1-8e04-2cf05da270f3
Discovery 2026-06-11
Entry 2026-06-12

Gitlab reports:

Improper Access Control issue in Group SAML Identity API impacts GitLab EE

Cross-site Scripting issue in Analytics Dashboard impacts GitLab EE

Denial of Service issue in Grape API JSON parsing middleware impacts GitLab CE/EE

HTML injection issue in certain group setting fields impacts GitLab EE

Denial of Service issue in Group Placeholder Reassignments API impacts GitLab CE/EE

Improper Access Control issue in Merge Requests API impacts GitLab CE/EE

Server-Side Request Forgery issue in Gitaly repository import impacts GitLab CE/EE

HTML injection issue in CI/CD Catalog impacts GitLab CE/EE

Improper Access Control issue in Security Inventory impacts GitLab EE

Authorization Bypass issue in Merge Request diff impacts GitLab CE/EE

Improper Access Control issue in Todos API impacts GitLab CE/EE

Improper Neutralization issue in Service Desk email template impacts GitLab CE/EE

References

CVE Name CVE-2026-10087
CVE Name CVE-2026-10733
CVE Name CVE-2026-1500
CVE Name CVE-2026-3553
CVE Name CVE-2026-6269
CVE Name CVE-2026-6277
CVE Name CVE-2026-6552
CVE Name CVE-2026-6976
CVE Name CVE-2026-7250
CVE Name CVE-2026-8589
CVE Name CVE-2026-9204
CVE Name CVE-2026-9694
URL https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-0-2-released/