GitLab 已修复了一个影响 GitLab CE/EE 的安全问题,该问题存在于所有 18.6 至 19.2.7(不含 19.2.7)、19.3 至 19.3.3(不含 19.3.3)以及 19.4 至 19.4.1(不含 19.4.1)的版本中。在竞态条件(race condition)下,MCP 搜索工具对共享状态的处理不当可能导致搜索结果在错误的用户上下文下返回。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89078 | 9.9 CRITICAL | Double Free in GitLab |
| CVE-2026-93577 | 9.9 CRITICAL | Integer Overflow or Wraparound in GitLab |
| CVE-2026-92470 | 7.7 HIGH | Missing Authorization in GitLab |
| CVE-2026-92874 | 5.4 MEDIUM | Incorrect Authorization in GitLab |
| CVE-2026-92530 | 4.3 MEDIUM | Use of Less Trusted Source in GitLab |
| CVE-2026-92529 | 4.3 MEDIUM | Incorrect Authorization in GitLab |
No comments yet