Executive brief
GitLab Enterprise Edition, a platform for software development and collaboration, contains a security flaw in its Code Quality reporting feature. An attacker with basic account access could create a malicious report that, when viewed by other users, captures and leaks their IP addresses. This could be used to track user locations or gather information for further targeted attacks against employees.
Technical details
A code injection vulnerability (CWE-94) exists in GitLab EE's Code Quality reports component. The flaw allows an authenticated attacker to embed specially crafted content within a report. When a victim views this report, the crafted content triggers a request that leaks the victim's IP address to the attacker. The attack requires network connectivity and user interaction (viewing the report). GitLab has released patches in versions 18.8.9, 18.9.5, and 18.10.3 to address this issue.
Affected products
- GitLab GitLab Enterprise Edition (EE) 18.0.0 to 18.8.8, 18.9.0 to 18.9.4, 18.10.0 to 18.10.2
Timeline
- 2026-04-08: advisory: GitLab released security patch 18.10.3, 18.9.5, and 18.8.9.
- 2026-04-08: disclosed: CVE-2026-1516 published.