CVE-2026-7471

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with control of a virtual registry upstream to make requests to internal hosts due to improper validation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

14 May 2026, 18:50

Type Values Removed Values Added
References () https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/ - () https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/ - Release Notes
References () https://gitlab.com/gitlab-org/gitlab/-/work_items/594196 - () https://gitlab.com/gitlab-org/gitlab/-/work_items/594196 - Broken Link
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
First Time Gitlab gitlab
Gitlab

14 May 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-14 06:16

Updated : 2026-05-14 18:50


NVD link : CVE-2026-7471

Mitre link : CVE-2026-7471

CVE.ORG link : CVE-2026-7471


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-918

Server-Side Request Forgery (SSRF)