Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials and tokens without transiting the expected proxy due to improper authorization checks on internal data emission endpoints.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Disclosure of Sensitive Credentials
Action: Apply Patch
AI Analysis

Impact

A flaw in GitLab allows an authenticated user to bypass expected proxy checks and read internal data emission endpoints that expose credentials and tokens. It results from missing authorization verification and can reveal who can reach those endpoints, compromising the confidentiality of the GitLab instance.

Affected Systems

The vulnerability affects GitLab Community Edition and Enterprise Edition from version 10.1.0 up to, but not including, 19.1.8, 19.2.6, and 19.3.2. Upgrading to GitLab 19.1.8, 19.2.6, 19.3.2 or any later release mitigates the issue.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate risk. The EPSS score is < 1%, indicating a very low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires endpoints; once authenticated, an attacker can read credentials that should otherwise be filtered through a proxy.

Generated by OpenCVE AI on September 28, 2026 at 21:44 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above.


OpenCVE Recommended Actions

  • Upgrade to GitLab 19.1.8, 19.2.6, 19.3.2 or a newer release to apply the vendor fix.
  • Limit network access to internal data emission endpoints, for example by configuring firewall rules or internal proxies so that only the GitLab application can reach those endpoints.
  • Apply least‑privilege access controls by restricting contributor and developer roles that can reach the sensitive credential endpoints.

Generated by OpenCVE AI on September 28, 2026 at 21:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-522
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials and tokens without transiting the expected proxy due to improper authorization checks on internal data emission endpoints.
Title Insertion of Sensitive Information Into Sent Data in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-201
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-09-20T00:45:43.401Z

Reserved: 2026-08-31T07:33:30.186Z

Link: CVE-2026-82837

cve-icon Vulnrichment

Updated: 2026-09-20T00:42:13.863Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T18:19:28.117

Modified: 2026-09-28T20:03:10.450

Link: CVE-2026-82837

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T21:45:06Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data

  • CWE-522

    Insufficiently Protected Credentials