GitLab 已修复了一个影响 GitLab CE/EE 的安全问题。该漏洞影响以下版本:19.2 至 19.2.7 之前、19.3 至 19.3.3 之前,以及 19.4 至 19.4.1 之前的所有版本。在特定条件下,该漏洞可能导致经过身份验证的用户在 GitLab 服务器上执行任意代码。问题根源在于:当在 CI/CD 配置中编译特制的正则表达式时,由于整数溢出缺陷,从而引发了安全风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89078 | 9.9 CRITICAL | Double Free in GitLab |
| CVE-2026-92470 | 7.7 HIGH | Missing Authorization in GitLab |
| CVE-2026-92874 | 5.4 MEDIUM | Incorrect Authorization in GitLab |
| CVE-2026-92530 | 4.3 MEDIUM | Use of Less Trusted Source in GitLab |
| CVE-2026-92529 | 4.3 MEDIUM | Incorrect Authorization in GitLab |
| CVE-2026-92628 | 3.1 LOW | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition' |
No comments yet