CVE-2026-2995: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to add email addresses to targeted user accounts due to improper sanitization of HTML content.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to add email addresses to targeted user accounts due to improper sanitization of HTML content.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-2995?
CVE-2026-2995 is considered a medium severity vulnerability due to its potential impact on user account security.
How do I fix CVE-2026-2995?
To remediate CVE-2026-2995, upgrade GitLab EE to version 18.8.8 or later, 18.9.4 or later, or 18.10.2 or later.
Who is affected by CVE-2026-2995?
CVE-2026-2995 affects authenticated users of GitLab EE versions up to 18.8.7, 18.9.3, and 18.10.1.
What type of vulnerability is CVE-2026-2995?
CVE-2026-2995 is an HTML injection vulnerability that arises from improper sanitization of HTML content.
Can CVE-2026-2995 lead to account takeover?
Yes, CVE-2026-2995 could allow an authenticated user to add email addresses to targeted user accounts, potentially leading to unauthorized access.