Medium severity5.4NVD Advisory· Published Jul 29, 2026· Updated Aug 3, 2026
CVE-2026-16553
CVE-2026-16553
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of upstream requests in virtual registries.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1
from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1+ 2 more
- (no CPE)range: from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=18.8.0,<19.0.5
- cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*
Patches
Vulnerability mechanics
References
1- docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/nvdRelease NotesVendor Advisory
News mentions
2- GitLab Fixes 13 Security Flaws That Can Leak Data, Alter Pipelines, and Crash ServersCyber Security News · Jul 30, 2026
- GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5GitLab Security Releases · Jul 29, 2026