Database/Control plane, storage & DevOps
GitLab CE/EE: Terraform state upload parameters let a project user read server files or DoS the instance
Impact
Improper parameter validation in the Terraform state upload endpoint lets an authenticated user with project-level permissions read restricted file contents on the GitLab server, or cause denial of service. On a self-managed instance this is file disclosure from the host that holds the infrastructure-as-code state for the cluster itself, plus a way for a low-privileged project member to take the instance down. GitLab's advisory does not enumerate which paths are reachable; treat anything readable by the GitLab service account as in play.
Who can reach it
Authenticated user holding project-level permissions on the instance, over the network. Attack complexity is rated high, so exploitation is not trivial.
What to do
Upgrade to GitLab 19.1.8, 19.2.6 or 19.3.2 (affected: 18.2.7 onward). Self-managed: patch and restart GitLab. GitLab.com is already patched.
References
Related entries
- Volcano (admission webhook server, unbounded HTTP request body): The Volcano webhook server accepts request bodies ofCVE-2026-44247 · Volcano (admission webhook server, unbounded HTTP request body)Medium
- HashiCorp Vault: slash injection in templated policy paths grants access to unintended pathsCVE-2026-5006 · HashiCorp Vault / Vault Enterprise (templated policy path rendering)Medium
- Renovate self-hosted: child processes inherit the full environment, exposing every secretCVE-2026-76227 · Renovate self-hosted (child process environment inheritance)Medium
- Ansible community.general OCAPI modules: TLS verification disabled, enclosure credentials exposedCVE-2026-87872 · Ansible community.general OCAPI modules (ocapi_command, ocapi_info)Medium
- rclone (S3 backend, redirect sanitization): When rclone's S3 backend follows a redirect it strips some sensitiveNCVD-2026-043-rclone-s3-backend-redirect-sanit · rclone (S3 backend, redirect sanitization)Medium
- SPI flash descriptor region configuration on a wide range of Supermicro boards: Any software running with sufficientCVE-2018-13787 · SPI flash descriptor region configuration on a wide range of Supermicro boardsMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.