FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Gitlab -- vulnerabilities

Affected packages
18.8.0 <= gitlab-ce < 18.8.4
18.7.0 <= gitlab-ce < 18.7.4
8.0.0 <= gitlab-ce < 18.6.6
18.8.0 <= gitlab-ee < 18.8.4
18.7.0 <= gitlab-ee < 18.7.4
8.0.0 <= gitlab-ee < 18.6.6

Details

VuXML ID 9d9940e7-071c-11f1-93ca-2cf05da270f3
Discovery 2026-02-10
Entry 2026-02-11

Gitlab reports:

Incomplete Validation issue in Web IDE impacts GitLab CE/EE

Denial of Service issue in GraphQL introspection impacts GitLab CE/EE

Denial of Service issue in JSON validation middleware impacts GitLab CE/EE

Cross-site Scripting issue in Code Flow impacts GitLab CE/EE

HTML Injection issue in test case titles impacts GitLab CE/EE

Denial of Service issue in Markdown processor impacts GitLab CE/EE

Denial of Service issue in Markdown Preview impacts GitLab CE/EE

Denial of Service issue in dashboard impacts GitLab EE

Server-Side Request Forgery issue in Virtual Registry impacts GitLab EE

Improper Validation issue in diff parser impacts GitLab CE/EE

Server-Side Request Forgery issue in Git repository import impacts GitLab CE/EE

Authorization Bypass issue in iterations API impacts GitLab EE

Missing Authorization issue in GLQL API impacts GitLab CE/EE

Stored HTML Injection issue in project label impacts GitLab CE/EE

Authorization Bypass issue in Pipeline Schedules API impacts GitLab CE/EE

References

CVE Name CVE-2025-12073
CVE Name CVE-2025-12575
CVE Name CVE-2025-14560
CVE Name CVE-2025-14592
CVE Name CVE-2025-14594
CVE Name CVE-2025-7659
CVE Name CVE-2025-8099
CVE Name CVE-2026-0595
CVE Name CVE-2026-0958
CVE Name CVE-2026-1080
CVE Name CVE-2026-1094
CVE Name CVE-2026-1282
CVE Name CVE-2026-1387
CVE Name CVE-2026-1456
CVE Name CVE-2026-1458
URL https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/