PT-2026-24714 · Gitlab · Gitlab Ce/Ee

St4Nly0N

·

Published

2026-03-11

·

Updated

2026-03-15

·

CVE-2026-1230

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions prior to 18.7.6 GitLab CE/EE versions 18.8 prior to 18.8.6 GitLab CE/EE versions 18.9 prior to 18.9.2
Description An authenticated user could potentially cause repository downloads to contain different code than displayed in the web interface. This is due to incorrect validation of branch references under specific conditions.
Recommendations Update GitLab CE/EE to version 18.7.6 or later. Update GitLab CE/EE to version 18.8.6 or later. Update GitLab CE/EE to version 18.9.2 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2026-03437
BIT-GITLAB-2026-1230
CVE-2026-1230

Affected Products

Gitlab Ce/Ee