Executive brief
GitLab is a platform used by software teams to manage and host their code and software packages. A security flaw was found where users with 'Developer' permissions could bypass protection rules for PyPI (Python) packages. This could allow an internal user to upload unauthorized or malicious software packages to restricted areas of the company's package registry.
Technical details
An authorization bypass vulnerability (CWE-639) exists in GitLab CE/EE's PyPI package registry component. The flaw is caused by improper authorization checks when validating package protection rules. An authenticated attacker with at least Developer-level permissions can exploit this to upload packages to restricted PyPI repositories, bypassing intended administrative constraints. This issue affects versions 17.6 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3. Users should upgrade to versions 18.9.7, 18.10.6, or 18.11.3 to mitigate the risk.
Affected products
- GitLab GitLab Community Edition (CE) / Enterprise Edition (EE) 17.6 to <18.9.7, 18.10 to <18.10.6, 18.11 to <18.11.3
Timeline
- 2026-05-13: patched: GitLab released versions 18.9.7, 18.10.6, and 18.11.3 to address the issue.
- 2026-05-14: disclosed: CVE-2026-3073 was published.