Executive brief
GitLab Enterprise Edition, a platform used for software development and version control, has a security flaw in its virtual registry component. This vulnerability could allow sensitive information, such as credentials, to be accidentally sent to an unauthorized server. An attacker with basic user access could potentially exploit this to gain access to private data or disrupt operations.
Technical details
GitLab Enterprise Edition (EE) contains an 'Insufficiently Protected Credentials' vulnerability (CWE-522) within its virtual registries feature. The flaw stems from improper handling of upstream requests, which under specific conditions, allows sensitive information to be disclosed to an unintended host. An authenticated attacker with network access can exploit this vulnerability to leak credentials or other sensitive data. The issue affects GitLab EE versions 18.8 through 19.0.5, 19.1 through 19.1.3, and 19.2 through 19.2.1. Patches have been released in versions 19.0.5, 19.1.3, and 19.2.1.
Affected products
- GitLab GitLab Enterprise Edition 18.8 to 19.0.5, 19.1 to 19.1.3, 19.2 to 19.2.1
Timeline
- 2026-07-29: advisory
- 2026-07-29: patched