CVE-2026-6515: Insufficient Session Expiration issue in virtual registry credentials validation impacts GitLab CE/EE
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed a user to use invalidated or incorrectly scoped credentials to access Virtual Registries under certain conditions.
Other sources
GitLab has remediated an issue that could have allowed a user to use invalidated or incorrectly scoped credentials to access Virtual Registries under certain conditions.
— GitLab
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.9.6Fixed in 18.10.4Fixed in 18.11.1 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.9.6 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.10.4 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.11.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-6515?
CVE-2026-6515 is classified with a high severity due to the potential for session hijacking.
How do I fix CVE-2026-6515?
You can fix CVE-2026-6515 by updating to GitLab CE/EE version 18.9.6, 18.10.4, or 18.11.1.
Which versions are affected by CVE-2026-6515?
CVE-2026-6515 affects GitLab CE/EE versions from 18.2 to before 18.9.6, 18.10 to before 18.10.4, and 18.11 to before 18.11.1.
What type of vulnerability is CVE-2026-6515?
CVE-2026-6515 is identified as an insufficient session expiration vulnerability.
What impact does CVE-2026-6515 have on security?
CVE-2026-6515 could allow users to leverage invalidated session credentials, compromising account security.