Gitlab · Gitlab · CVE-2026-3848
**Name of the Vulnerable Software and Affected Versions**
GitLab CE/EE versions 8.11 through 18.7.5
GitLab CE/EE versions 18.8 through 18.8.5
GitLab CE/EE versions 18.9 through 18.9.1
**Description**
An issue in GitLab CE/EE could allow an authenticated user to make unintended internal requests through proxy environments. This is due to improper input validation within the import functionality.
**Recommendations**
GitLab versions prior to 18.7.6 should be updated.
GitLab versions prior to 18.8.6 should be updated.
GitLab versions prior to 18.9.2 should be updated.