FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Gitlab -- vulnerabilities

Affected packages
18.10.0 <= gitlab-ce < 18.10.1
18.9.0 <= gitlab-ce < 18.9.3
7.11.0 <= gitlab-ce < 18.8.7
18.10.0 <= gitlab-ee < 18.10.1
18.9.0 <= gitlab-ee < 18.9.3
7.11.0 <= gitlab-ee < 18.8.7

Details

VuXML ID b933083e-2b2e-11f1-b60a-2cf05da270f3
Discovery 2026-03-25
Entry 2026-03-29

Gitlab reports:

Improper Handling of Parameters issue in Jira Connect installations impacts GitLab CE/EE

Cross-Site Request Forgery issue in GLQL API impacts GitLab CE/EE

HTML Injection in vulnerability report impacts GitLab EE

Denial of Service issue in GraphQL API impacts GitLab CE/EE

Improper Access Control issue in WebAuthn 2FA impacts GitLab CE/EE

Improper Access Control issue in GraphQL query impacts GitLab EE

Denial of Service issue in CI configuration processing impacts GitLab CE/EE

Denial of Service issue in webhook configuration impacts GitLab CE/EE

Cross-site Scripting issue in Mermaid diagram renderer impacts GitLab CE/EE

Improper Access Control issue in Merge Requests impacts GitLab CE/EE

Access Control issue in GraphQL API impacts GitLab EE

Incorrect Authorization issue in authorization caching impacts GitLab EE

References

CVE Name CVE-2025-13078
CVE Name CVE-2025-13436
CVE Name CVE-2025-14595
CVE Name CVE-2026-1724
CVE Name CVE-2026-2370
CVE Name CVE-2026-2726
CVE Name CVE-2026-2745
CVE Name CVE-2026-2973
CVE Name CVE-2026-2995
CVE Name CVE-2026-3857
CVE Name CVE-2026-3988
CVE Name CVE-2026-4363
URL https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/