CVE-2026-12635: Reliance on Reverse DNS Resolution for a Security-Critical Action in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to make requests to internal network resources through mirror synchronization due to improper URL validation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.11.6 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.0.3 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12635?
The severity of CVE-2026-12635 is classified as low with a score of 3.1.
How do I fix CVE-2026-12635?
To fix CVE-2026-12635, upgrade GitLab to versions 18.11.6, 19.0.3, or 19.1.1 or later.
What impact does CVE-2026-12635 have on GitLab?
CVE-2026-12635 could allow an authenticated user with maintainer-role permissions to access internal network resources under certain conditions.
Which versions of GitLab are affected by CVE-2026-12635?
CVE-2026-12635 affects all versions of GitLab CE/EE from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1.
Is user interaction required for CVE-2026-12635 to be exploited?
No, user interaction is not required for CVE-2026-12635 to be exploited.