Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web interface differed from the content available for download, due to improper handling of Git reference name resolution.
Published: 2026-07-08
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GitLab exposes a flaw that, under certain conditions, allows an authenticated user to create a new repository where the files shown in the web interface differ from the files retrieved when the repository is downloaded. This mismatch occurs because the system does not resolve Git reference names correctly during repository uploads. The result is a situation where the displayed content can mislead users, potentially enabling malicious actors to present altered or misleading content to those who rely on the web view.

Affected Systems

GitLab Community Edition and Enterprise Edition across all releases from version 16.5 up to but not including 18.11.7, from 19.0 up to but not including 19.0.4, and from 19.1 up to but not including 19.1.2. The affected offerings include both source and packaged distributions as noted by the vendor.

Risk and Exploitability

The CVSS score of 3.5 classifies the vulnerability as low severity. The EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA KEV, which suggests no known active exploitation. The likely attack vector requires an authenticated user with permission to create new repositories; no remote code execution or network-based attack is possible. Overall, the risk is modest and limited to confusing or misleading users within the compromised environment.

Generated by OpenCVE AI on July 26, 2026 at 16:56 UTC.

Remediation

Vendor Solution

Upgrade to versions 18.11.7, 19.0.4, 19.1.2 or above.


OpenCVE Recommended Actions

  • Upgrade to GitLab 18.11.7 or newer, 19.0.4 or newer, or 19.1.2 or newer as recommended by the vendor
  • Restrict repository creation privileges to trusted users only
  • Monitor for suspicious or infected repository uploads

Generated by OpenCVE AI on July 26, 2026 at 16:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web interface differed from the content available for download, due to improper handling of Git reference name resolution.
Title Use of Incorrectly-Resolved Name or Reference in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-706
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-07-09T13:53:34.205Z

Reserved: 2025-10-30T14:05:29.287Z

Link: CVE-2025-12506

cve-icon Vulnrichment

Updated: 2026-07-09T13:53:25.034Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T17:00:14Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference