GPU VulnDB

Database/Control plane, storage & DevOps

GitLab: unauthenticated GraphQL requests can read CI/CD job traces containing secret variable values

CVSS 3.7CVE-2026-4523Control plane, storage & DevOpscurated

Impact

On a self-hosted GitLab that builds container images, driver bundles or Terraform/Helm rollouts for a GPU fleet, job logs routinely contain expanded CI/CD variables - registry credentials, cloud service-account keys, kubeconfig tokens. Improper authorization in the GraphQL API let an unauthenticated caller read those traces, so any secret that was echoed or leaked into a job log becomes readable without an account. The practical blast radius is whatever those pipeline credentials can reach: the image registry, the cluster the pipeline deploys to, or node provisioning. GitLab rates it 3.7 because exploitation depends on conditions it does not detail (AC:H), but the value of what leaks is set by your own pipeline hygiene, not by the score.

Who can reach it

Network reach to the GitLab instance's GraphQL endpoint. No authentication required. Instances exposed only inside the management network are correspondingly harder to reach.

What to do

Upgrade to GitLab 19.4.1, 19.3.3 or 19.2.7 (all versions from 15.11 are affected) and restart the application - a normal GitLab upgrade window, no fleet impact. Treat it as a possible secret disclosure: rotate any credential that pipelines may have printed into job logs, and re-check that masked/protected variables are actually set that way.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.