Junglewise Threat Intelligence

CVE-2026-16553: GitLab Enterprise Edition credential disclosure in virtual registries

CVE-2026-16553 · Severity: medium · CVSS 5.4 · Published 2026-07-29

Executive brief

GitLab Enterprise Edition, a platform used for software development and version control, has a security flaw in its virtual registry component. This vulnerability could allow sensitive information, such as credentials, to be accidentally sent to an unauthorized server. An attacker with basic user access could potentially exploit this to gain access to private data or disrupt operations.

Technical details

GitLab Enterprise Edition (EE) contains an 'Insufficiently Protected Credentials' vulnerability (CWE-522) within its virtual registries feature. The flaw stems from improper handling of upstream requests, which under specific conditions, allows sensitive information to be disclosed to an unintended host. An authenticated attacker with network access can exploit this vulnerability to leak credentials or other sensitive data. The issue affects GitLab EE versions 18.8 through 19.0.5, 19.1 through 19.1.3, and 19.2 through 19.2.1. Patches have been released in versions 19.0.5, 19.1.3, and 19.2.1.

Affected products

  • GitLab GitLab Enterprise Edition 18.8 to 19.0.5, 19.1 to 19.1.3, 19.2 to 19.2.1

Timeline

  • 2026-07-29: advisory
  • 2026-07-29: patched

References

Related threats