GPU VulnDB

Database/Control plane, storage & DevOps

GitLab: developer-role user can replace package file content and hide packages from owners

CVSS 4.3CVE-2026-7514Control plane, storage & DevOpscurated

Impact

Improper authorization in the Generic Package Registry lets a user with only developer-role permissions substitute the content of an existing package file and hide packages from their owners. Where the registry is the distribution point for internal artifacts - driver bundles, container build inputs, model or dataset archives pulled by cluster jobs - this is a supply-chain integrity problem inside the organisation: consumers fetch the same package name and version and get different bytes, and the owner does not see the package to notice. The flaw has been present since GitLab 13.9, so any affected instance has had a long exposure window. It needs a developer account on the project, not an anonymous attacker.

Who can reach it

An authenticated GitLab user with developer-role permissions on the project, over the network to the GitLab instance.

What to do

Upgrade self-managed GitLab to 19.1.8, 19.2.6, or 19.3.2. Package upgrade and service restart on the GitLab host. Given the long exposure window, verify checksums of generic packages that cluster jobs consume against a trusted copy rather than assuming the registry contents are intact.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.