CVE-2026-3848: Improper Neutralization of CRLF Sequences issue impacts GitLab CE/EE
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to make unintended internal requests through proxy environments under certain conditions due to improper input validation in import functionality.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to make unintended internal requests through proxy environments under certain conditions due to improper input validation in import functionality.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-3848?
CVE-2026-3848 has a medium severity as it allows authenticated users to perform unintended internal requests.
How do I fix CVE-2026-3848?
To fix CVE-2026-3848, update your GitLab CE or EE to versions 18.7.6, 18.8.6, or 18.9.2.
Which versions are affected by CVE-2026-3848?
CVE-2026-3848 affects GitLab CE/EE versions from 8.11 prior to 18.7.6, 18.8 prior to 18.8.6, and 18.9 prior to 18.9.2.
Who is impacted by CVE-2026-3848?
All users running affected versions of GitLab CE or EE are impacted by CVE-2026-3848.
Is there a workaround for CVE-2026-3848?
No specific workaround is mentioned for CVE-2026-3848; upgrading to the patched versions is recommended.