GitLab 已修复了 GitLab CE/EE 中的一个漏洞,影响所有 19.2 之前至 19.2.7 之前、19.3 之前至 19.3.3 之前以及 19.4 之前至 19.4.1 之前的版本。在特定条件下,该漏洞可能导致经过身份验证的用户通过解析 CI/CD 配置中精心构造的正则表达式时引发的双重释放(double free)问题,在 GitLab 服务器上执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93577 | 9.9 CRITICAL | Integer Overflow or Wraparound in GitLab |
| CVE-2026-92470 | 7.7 HIGH | Missing Authorization in GitLab |
| CVE-2026-92874 | 5.4 MEDIUM | Incorrect Authorization in GitLab |
| CVE-2026-92530 | 4.3 MEDIUM | Use of Less Trusted Source in GitLab |
| CVE-2026-92529 | 4.3 MEDIUM | Incorrect Authorization in GitLab |
| CVE-2026-92628 | 3.1 LOW | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition' |
No comments yet