CVE-2026-1516: Improper Control of Generation of Code ('Code Injection') in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of users viewing the report via specially crafted content.
Other sources
GitLab has remediated an issue that in Code Quality reports could have allowed an authenticated user to leak IP addresses of users viewing the report via specially crafted content.
— GitLab
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.8.9Fixed in 18.9.5Fixed in 18.10.3 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.8.9 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.9.5 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.10.3
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-1516?
CVE-2026-1516 is rated as a moderate severity vulnerability due to the potential for code injection.
How do I fix CVE-2026-1516?
To remediate CVE-2026-1516, upgrade to GitLab EE version 18.8.9, 18.9.5, or 18.10.3 or later.
Who is affected by CVE-2026-1516?
CVE-2026-1516 affects all GitLab EE versions from 18.0.0 through 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3.
What kind of issue is CVE-2026-1516?
CVE-2026-1516 is an improper control of code generation vulnerability, leading to potential code injection.
Can CVE-2026-1516 lead to data leakage?
Yes, CVE-2026-1516 could allow authenticated users to leak sensitive information such as IP addresses.