CVE-2026-16553: Insufficiently Protected Credentials in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of upstream requests in virtual registries.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.0.5 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.1.3 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16553?
CVE-2026-16553 has a medium severity rating of 5.4.
How do I fix CVE-2026-16553?
To fix CVE-2026-16553, upgrade GitLab EE to version 19.0.5, 19.1.3, or 19.2.1 or later.
What are the affected versions for CVE-2026-16553?
CVE-2026-16553 affects GitLab EE versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1.
What kind of information is disclosed due to CVE-2026-16553?
CVE-2026-16553 may lead to the disclosure of some sensitive information to unintended hosts.
What is the cause of CVE-2026-16553?
CVE-2026-16553 is caused by improper handling of upstream requests in GitLab.