Junglewise Threat Intelligence

CVE-2026-2238: GitLab improper authorization in Rapid Diffs component

CVE-2026-2238 · Severity: medium · CVSS 5.3 · Published 2026-06-25

Technologies: GitLab Community Edition, GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab has fixed a security flaw in its software development platform that could allow unauthorized individuals to view confidential information. Specifically, an unauthenticated user could see references to private, confidential issues within public projects. This could lead to the exposure of sensitive internal project details or security discussions that were intended to remain hidden from the public.

Technical details

An improper authorization vulnerability (CWE-862) exists in GitLab CE/EE within the Rapid Diffs component. The flaw allows an unauthenticated attacker to view references to confidential issues in public projects due to missing or insufficient authorization checks. The vulnerability affects versions 17.5 through 18.11.6, 19.0 through 19.0.3, and 19.1 through 19.1.1. Attackers can exploit this over the network without any user interaction or special privileges. GitLab has released patches in versions 18.11.6, 19.0.3, and 19.1.1 to address this issue.

Affected products

  • GitLab GitLab Community Edition (CE) 17.5 to 18.11.6, 19.0 to 19.0.3, 19.1 to 19.1.1
  • GitLab GitLab Enterprise Edition (EE) 17.5 to 18.11.6, 19.0 to 19.0.3, 19.1 to 19.1.1

Timeline

  • 2026-06-24: patched: GitLab released versions 19.1.1, 19.0.3, 18.11.6 containing the fix.
  • 2026-06-25: disclosed: Vulnerability details published by GitLab and NVD.

References

Related threats