Database/Control plane, storage & DevOps
GitLab: crafted Git ref names make the web UI show different content than the downloaded archive
Impact
Improper handling of Git reference name resolution let an authenticated user create a repository whose content as rendered in the GitLab web interface differs from the content served for download. That is a review-integrity problem rather than a code-execution one: a reviewer approving what the UI shows is not approving what a CI runner or a build job actually fetches. For a GPU fleet whose container images, Dockerfiles, CUDA build recipes and Kubernetes manifests flow through GitLab, it means a change that looks clean in the merge request can ship different bytes into an image that later runs on every node. Confidentiality and availability are unaffected; the impact is integrity of what gets built and deployed.
Who can reach it
Any authenticated GitLab user who can create a repository or push refs to one. No admin rights needed; exploitation depends on someone reviewing or consuming the affected repository.
What to do
Upgrade GitLab CE/EE to 18.11.7, 19.0.4 or 19.1.2 (affected: 16.5 up to those releases) and restart the GitLab services - for Omnibus a gitlab-ctl reconfigure/restart, for the Helm chart a rolling restart of the web and Gitaly pods. No node reboot and no downtime for GPU workloads. Worth pairing with a check of recently merged changes in any repository that feeds image builds, since the fix does not tell you whether the divergence was ever used.
References
Related entries
- Kibana: Open redirect leading to SSRF via a specially crafted URLCVE-2025-25012 · KibanaMedium
- GitLab EE: developer-role user can influence the execution environment of Pipeline Execution Policy jobsCVE-2026-15387 · GitLab EE (Pipeline Execution Policy enforcement jobs, job dependency handling)Medium
- GitLab EE: Security Manager role can run arbitrary CI/CD jobs and read protected variablesCVE-2026-16794 · GitLab EE (compliance framework management authorization)Medium
- GitLab EE: authenticated user can view restricted group configuration settingsCVE-2026-18244 · GitLab EE (group settings page authorization)Medium
- GitLab EE: GraphQL query exposes policy configuration from an unauthorized namespaceCVE-2026-18433 · GitLab EE (GraphQL query for namespace policy configuration)Medium
- NetApp ONTAP S3 NAS bucket directory listing: An authenticated S3 user lists the contents of directories they have noCVE-2026-22052 · NetApp ONTAP S3 NAS bucket directory listingMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.