GPU VulnDB

Database/Control plane, storage & DevOps

GitLab EE: Duo Chat GraphQL subscription leaks Advanced Search config and credentials

CVSS 9.9CVE-2026-87719Control plane, storage & DevOpscurated

Impact

An authenticated user with Duo Chat access can pass a crafted GraphQL subscription argument that bypasses serialization and performs a server-side object lookup, returning Advanced Search instance configuration and the credentials embedded in it. That typically means the Elasticsearch/OpenSearch endpoint and its authentication material, which in a self-managed deployment often sits on the same internal network as the rest of the CI and artifact infrastructure. Any developer account on the instance is enough, so this converts ordinary user access into instance-level secret disclosure.

Who can reach it

Any authenticated GitLab user who has Duo Chat enabled for them, over the normal web/GraphQL endpoint. No admin role required.

What to do

Upgrade to GitLab 19.1.8, 19.2.6 or 19.3.2 (EE versions from 18.3 onward are affected) and restart the application. Rotate the Advanced Search credentials afterwards, since the fix does not invalidate anything already disclosed. Disabling Duo Chat removes the exposed path if an upgrade window is not available immediately.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.