CVE-2026-1094: Improper Validation of Unsafe Equivalence in Input in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an authenticated developer to hide specially crafted file changes from the WebUI.
Other sources
GitLab has remediated an issue that could have allowed an authenticated developer to hide specially crafted file changes from the WebUI.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-1094?
The severity of CVE-2026-1094 is classified as moderate, as it allows authenticated users to hide file changes.
How do I fix CVE-2026-1094?
To fix CVE-2026-1094, upgrade GitLab to version 18.8.4 or later.
Who is affected by CVE-2026-1094?
CVE-2026-1094 affects all versions of GitLab CE/EE from 18.8.0 to 18.8.3.
What does CVE-2026-1094 exploit?
CVE-2026-1094 exploits improper validation in the diff parser to hide file changes from the WebUI.
Is authentication required to exploit CVE-2026-1094?
Yes, CVE-2026-1094 requires authentication as it can only be exploited by authenticated developers.