CVE-2026-1282: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to inject malicious content into project labels titles.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to inject content into project labels titles.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-1282?
CVE-2026-1282 is considered a high severity vulnerability due to its potential for enabling stored HTML injections in project labels.
How do I fix CVE-2026-1282?
To fix CVE-2026-1282, upgrade to GitLab version 18.6.6, 18.7.4, or 18.8.4.
Who is affected by CVE-2026-1282?
CVE-2026-1282 affects all versions of GitLab CE/EE from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4.
What type of vulnerability is CVE-2026-1282?
CVE-2026-1282 is a stored HTML injection vulnerability that can allow an authenticated user to inject malicious content.
Is there any public documentation for CVE-2026-1282?
Yes, public documentation regarding CVE-2026-1282 can be found in the release notes of GitLab.