Medium severity5.3NVD Advisory· Published Jun 25, 2026· Updated Jun 26, 2026
CVE-2026-2238
CVE-2026-2238
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to view confidential issue references on public projects due to improper authorization checks.
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: >=17.5.0,<18.11.6
- cpe:2.3:a:gitlab:gitlab:19.1.0:*:*:*:*:*:*:*
- Range: from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1
Patches
Vulnerability mechanics
References
2- docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/nvdRelease NotesVendor Advisory
- hackerone.com/reports/3543011nvdPermissions Required
News mentions
0No linked articles in our index yet.