CVE-2026-1230

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause repository downloads to contain different code than displayed in the web interface due to incorrect validation of branch references under certain circumstances.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

17 Mar 2026, 20:55

Type Values Removed Values Added
First Time Gitlab
Gitlab gitlab
Summary
  • (es) GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 1.0 anteriores a la 18.7.6, la 18.8 anteriores a la 18.8.6, y la 18.9 anteriores a la 18.9.2 que podría haber permitido a un usuario autenticado causar que las descargas del repositorio contuvieran código diferente al mostrado en la interfaz web debido a una validación incorrecta de las referencias de rama bajo ciertas circunstancias.
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
References () https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/ - () https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/ - Release Notes, Vendor Advisory
References () https://gitlab.com/gitlab-org/gitlab/-/work_items/587002 - () https://gitlab.com/gitlab-org/gitlab/-/work_items/587002 - Broken Link
References () https://hackerone.com/reports/3505165 - () https://hackerone.com/reports/3505165 - Permissions Required

11 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 16:16

Updated : 2026-03-17 20:55


NVD link : CVE-2026-1230

Mitre link : CVE-2026-1230

CVE.ORG link : CVE-2026-1230


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-706

Use of Incorrectly-Resolved Name or Reference