CVE-2026-10712: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.11.6 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.0.3 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10712?
The severity of CVE-2026-10712 is rated as high with a score of 8.
How do I fix CVE-2026-10712?
To fix CVE-2026-10712, upgrade GitLab to version 18.11.6 or later, 19.0.3 or later, or 19.1.1 or later.
What type of vulnerability is CVE-2026-10712?
CVE-2026-10712 is classified as a Cross-site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-10712?
CVE-2026-10712 affects all GitLab CE and EE versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1.
What impact does CVE-2026-10712 have on users?
CVE-2026-10712 could allow unauthenticated users to execute arbitrary JavaScript in a user's browser session.