Executive brief
GitLab is a platform used by organizations to manage software development and source code. A vulnerability was identified where users with 'maintainer' permissions could potentially make unauthorized requests to internal network resources through the repository mirroring feature. This could allow an attacker to probe or interact with private internal systems that are not intended to be accessible from the GitLab application.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in GitLab CE/EE's repository mirroring component. The issue stems from improper URL validation and a reliance on reverse DNS resolution for security-critical actions (CWE-350). An authenticated attacker with at least 'maintainer' role permissions can exploit this during mirror synchronization to force the GitLab server to make requests to internal network resources. While the vendor assigned a CVSS score of 0.0, the vulnerability is categorized as a low-severity SSRF. Patches are available in versions 18.11.6, 19.0.3, and 19.1.1.
Affected products
- GitLab GitLab CE/EE 8.3 to 18.11.6, 19.0 to 19.0.3, 19.1 to 19.1.1
Timeline
- 2026-06-24: patched: GitLab released versions 19.1.1, 19.0.3, 18.11.6 containing the fix.
- 2026-06-25: advisory: NVD published the CVE record.