6.8

CVSS3.1

CVE-2026-2745 - Authentication Bypass Using an Alternate Path or Channel in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to bypass WebAuthn two-factor authentication and gain unauthorized access to user accounts due to inconsistent …

πŸ“… Published: March 25, 2026, 4:34 p.m. πŸ”„ Last Modified: March 26, 2026, 11:34 a.m.

4.3

CVSS3.1

CVE-2026-2726 - Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to perform unauthorized actions on merge requests in other projects due to improper access control during cross-…

πŸ“… Published: March 25, 2026, 4:34 p.m. πŸ”„ Last Modified: March 26, 2026, 6:30 p.m.

5.4

CVSS3.1

CVE-2026-2973 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to execute arbitrary JavaScript in a user's browser due to improper sanitization of entity-encoded content in Mer…

πŸ“… Published: March 25, 2026, 4:34 p.m. πŸ”„ Last Modified: March 26, 2026, 5:43 p.m.

7.7

CVSS3.1

CVE-2026-2995 - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to add email addresses to targeted user accounts due to improper sanitization of HTML content.

πŸ“… Published: March 25, 2026, 4:33 p.m. πŸ”„ Last Modified: March 26, 2026, 5:42 p.m.

8.1

CVSS3.1

CVE-2026-3857 - Cross-Site Request Forgery (CSRF) in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to execute arbitrary GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.

πŸ“… Published: March 25, 2026, 4:33 p.m. πŸ”„ Last Modified: March 26, 2026, 11:34 a.m.

7.5

CVSS3.1

CVE-2026-3988 - Inefficient Algorithmic Complexity in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to cause a denial of service by making the GitLab instance unresponsive due to improper input validation in Gra…

πŸ“… Published: March 25, 2026, 4:33 p.m. πŸ”„ Last Modified: March 26, 2026, 5:42 p.m.

4.6

CVSS3.1

CVE-2026-27659 - CSRF vulnerability in UpdateAccessControlPolicyActiveStatus endpoint

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to properly validate CSRF tokens in the /api/v4/access_control_policies/{policy_id}/activate endpoint, which allows an attacker to trick an admin into changing access control policy active status via …

πŸ“… Published: March 25, 2026, 4:33 p.m. πŸ”„ Last Modified: March 26, 2026, 11:34 a.m.

4.3

CVSS3.1

CVE-2026-20719 - DoS via URL Previews Rendering Malicious SVGs

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to prevent rendering of external SVGs on link embeds which allows unauthenticated users to crash the Mattermost webapp and desktop app via creating an issue or PR on GitHub.. Mattermost Advisory ID: M…

πŸ“… Published: March 25, 2026, 4:30 p.m. πŸ”„ Last Modified: March 26, 2026, 5:11 p.m.

5.7

CVSS3.1

CVE-2026-27656 - Account Takeover via Substring Matching in OpenID Connect Authentication

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user accounts via an overly permissive substring matching flaw in th…

πŸ“… Published: March 25, 2026, 4:28 p.m. πŸ”„ Last Modified: March 26, 2026, 11:34 a.m.

4.3

CVSS3.1

CVE-2026-26233 - Denial of Service via HTTP/2 single packet attack on login endpoint

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to rate limit login requests which allows unauthenticated remote attackers to cause denial of service (server crash and restart) via HTTP/2 single packet attack with 100+ parallel login requests.. Mat…

πŸ“… Published: March 25, 2026, 4:24 p.m. πŸ”„ Last Modified: March 26, 2026, 11:34 a.m.
Total resulsts: 340628
Page 28 of 34,063
Β« previous page Β» next page
Filters