GitLab released security updates for Community Edition and Enterprise Edition, shipping versions 18.10.3, 18.9.5, and 18.8.9 to address multiple vulnerabilities tracked as CVE-2026-5173, CVE-2026-1092, CVE-2025-12664, and CVE-2026-1101. The patched issues include a high-severity flaw that could allow unintended server-side method invocation over WebSocket connections, along with several denial-of-service weaknesses affecting the Terraform state lock API and the GraphQL API.
The release also fixes medium- and low-severity bugs including cross-site scripting in analytics dashboards, code-injection-related IP leakage in Code Quality reports, authorization weaknesses in APIs and custom roles, and information disclosure through GraphQL queries and CSV export. GitLab said GitLab.com had already been patched, GitLab Dedicated customers did not need to take action, and self-managed customers should upgrade immediately; the company added that the updates require no new migrations and should not cause downtime in multi-node deployments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CVE records for CVE-2026-5173, CVE-2026-1092, CVE-2025-12664, and CVE-2026-1101 were published on April 8, 2026. These records correspond to vulnerabilities addressed in the GitLab security patch release.
GitLab released security patch versions 18.10.3, 18.9.5, and 18.8.9 for GitLab Community Edition and Enterprise Edition on April 8, 2026, and urged self-managed customers to upgrade immediately. The patches addressed multiple vulnerabilities including a high-severity unintended server-side method invocation issue over websocket connections, several denial-of-service flaws, and additional medium- and low-severity bugs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourcecve.org
Open sourcecve.org
Open sourcecve.org
Open sourcedocs.gitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.