CVE-2026-10733: Improper Restriction of Rendered UI Layers or Frames in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that could have allowed an authenticated user to cause denial of service on the CI/CD Catalog page due to improper sanitization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.10.8 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.11.5 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10733?
The severity of CVE-2026-10733 is medium with a score of 4.3.
How do I fix CVE-2026-10733?
To fix CVE-2026-10733, upgrade to GitLab versions 18.10.8, 18.11.5, 19.0.2 or higher.
What types of systems are affected by CVE-2026-10733?
CVE-2026-10733 affects GitLab Community Edition (CE) and Enterprise Edition (EE) versions before the specified patched versions.
What is the impact of CVE-2026-10733?
CVE-2026-10733 could allow an authenticated user to cause a denial of service on the CI/CD Catalog page.
Is CVE-2026-10733 a critical vulnerability?
No, CVE-2026-10733 is classified as a medium severity vulnerability.