Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to version 18.8.4 or above.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 12 Feb 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitlab gitlab
|
|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
|
| Vendors & Products |
Gitlab gitlab
|
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an authenticated developer to hide specially crafted file changes from the WebUI. | |
| Title | Improper Validation of Unsafe Equivalence in Input in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitaly |
|
| Weaknesses | CWE-1289 | |
| CPEs | cpe:2.3:a:gitlab:gitaly:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitaly |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-02-11T21:18:35.282Z
Reserved: 2026-01-16T21:33:12.365Z
Link: CVE-2026-1094
Updated: 2026-02-11T21:18:32.874Z
Status : Analyzed
Published: 2026-02-11T12:16:04.263
Modified: 2026-02-12T21:19:23.863
Link: CVE-2026-1094
No data.
OpenCVE Enrichment
Updated: 2026-04-18T12:45:45Z