GPU VulnDB

Database/Control plane, storage & DevOps

GitLab CE/EE: improper authorization on internal endpoints exposes credentials and tokens

CVSS 5.3CVE-2026-82837Control plane, storage & DevOpscurated

Impact

GitLab's internal data emission endpoints did not enforce the expected authorization, letting a user reach sensitive credentials and tokens without transiting the expected proxy. For a fleet that builds container images, ships model artifacts and deploys cluster manifests out of GitLab, leaked CI credentials and tokens are a path into the registry and the deploy pipeline rather than a contained web-app bug. The record rates confidentiality impact as low with no integrity or availability effect, and GitLab does not publish the endpoint detail; treat it as credential exposure of uncertain breadth. Affects 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.

Who can reach it

Network-reachable against the GitLab instance. The vendor summary says an authenticated user, while the scored vector states no privileges required - assume anyone who can reach the instance's HTTP endpoints until GitLab clarifies.

What to do

Upgrade self-managed GitLab to 19.1.8, 19.2.6 or 19.3.2. That is a standard GitLab package upgrade and service restart on the instance, not a fleet-wide action. After upgrading, rotate CI/CD variables, deploy tokens and personal access tokens that the instance held, since the flaw is credential disclosure. GitLab.com is already patched.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.