Executive brief
GitLab Enterprise Edition, a platform used for software development and collaboration, contained a vulnerability in its Duo Workflows feature. This flaw could allow an unauthorized user to access sensitive information that was previously committed to a project. Such exposure could lead to the theft of credentials, proprietary code, or other confidential business data.
Technical details
An information disclosure vulnerability exists in GitLab EE versions 19.1.x prior to 19.1.1 within the Duo Workflows component. The root cause is insufficient output filtering, which fails to properly redact or block sensitive information that has been committed to a project. An attacker can exploit this over the network to exfiltrate sensitive data. While the NVD record suggests no authentication is required (PR:N), GitLab's own advisory indicates the issue may be triggered 'under certain conditions' by a user. The vulnerability has been remediated in version 19.1.1.
Affected products
- GitLab GitLab Enterprise Edition 19.1 before 19.1.1
Timeline
- 2026-06-24: patched: GitLab released versions 19.1.1, 19.0.3, and 18.11.6 to address this and other issues.
- 2026-06-25: advisory: CVE-2026-12053 published.