Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitLab Security Alert: Critical XSS and DoS Flaws Fixed

GitLab Security Alert: Critical XSS and DoS Flaws Fixed

Posted on March 12, 2026 By CWS

GitLab has released critical security patches for both its Community Edition (CE) and Enterprise Edition (EE) to mitigate multiple vulnerabilities identified in recent assessments.

Critical Vulnerabilities Addressed

The security updates, encapsulated in versions 18.9.2, 18.8.6, and 18.7.6, tackle a total of 15 security concerns. Among these, the most severe is a Cross-Site Scripting (XSS) vulnerability with a CVSS score of 8.7, identified as CVE-2026-1090. This flaw affects GitLab’s Markdown placeholder processing and can be exploited by authenticated attackers to execute malicious JavaScript, leading to potential unauthorized access or session hijacking.

In addition to the XSS flaw, the update also rectifies three high-severity Denial-of-Service (DoS) vulnerabilities. These include a flaw in the GraphQL API, which allows specially crafted requests to trigger uncontrolled recursion, resulting in resource exhaustion. Another vulnerability involves the repository archive endpoints, and improper JSON payload validation in the protected branches API that could lead to service disruption.

Additional Security Enhancements

Beyond the high-severity issues, GitLab addressed several medium and low-severity bugs. Noteworthy fixes include resolving DoS risks associated with webhook custom headers and endpoints, neutralizing improper CRLF sequences, and correcting access control issues within the runners API. These updates are crucial for preventing unauthorized access to sensitive information and maintaining overall system integrity.

The security patch also addresses information disclosure vulnerabilities affecting confidential issues, ensuring that sensitive data remains protected from potential exposure.

Action Required for Administrators

Administrators of self-managed GitLab instances are advised to update their installations promptly to versions 18.9.2, 18.8.6, or 18.7.6 to safeguard their systems. While single-node setups will experience brief downtime during database migrations, multi-node environments can employ zero-downtime upgrade procedures. Users on GitLab.com and GitLab Dedicated are already secure with the patched versions and need no further action.

GitLab plans to release detailed vulnerability reports on its issue tracker 30 days post-patch release, allowing administrators to stay informed about the issues addressed.

Stay updated with the latest cybersecurity news by following us on Google News, LinkedIn, and X. For those interested in featuring their stories, feel free to contact us.

Cyber Security News Tags:API vulnerabilities, Cybersecurity, DoS attack, enterprise security, GitLab, security update, software patch, software update, vulnerability fix, XSS vulnerability

Post navigation

Previous Post: Microsoft Office Flaw Allows Dangerous Code Execution
Next Post: New Android Malware Threatens Pix Payments and Banking Apps

Related Posts

Hackers Weaponize Fake Microsoft Teams Site to Deploy Odyssey macOS Stealer Hackers Weaponize Fake Microsoft Teams Site to Deploy Odyssey macOS Stealer Cyber Security News
Threat Actors Using ViperSoftX Malware to Exfiltrate Sensitive Details Threat Actors Using ViperSoftX Malware to Exfiltrate Sensitive Details Cyber Security News
AI Discovers Decade-Old RCE Flaw in Apache ActiveMQ AI Discovers Decade-Old RCE Flaw in Apache ActiveMQ Cyber Security News
Stellantis, the Maker of Citroën, FIAT, Jeep, and Other Cars, Confirms Data Breach Stellantis, the Maker of Citroën, FIAT, Jeep, and Other Cars, Confirms Data Breach Cyber Security News
Malware Detected in Hugging Face Repository with 200k Downloads Malware Detected in Hugging Face Repository with 200k Downloads Cyber Security News
Enhancing Online Shopping Security for Better Deals Enhancing Online Shopping Security for Better Deals Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection
  • OceanLotus Targets Vietnamese Firms with SPECTRALVIPER
  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection
  • OceanLotus Targets Vietnamese Firms with SPECTRALVIPER
  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark