Junglewise Threat Intelligence

CVE-2026-5173: GitLab CE/EE unauthorized method invocation via WebSockets

CVE-2026-5173 · Severity: high · CVSS 8.5 · Published 2026-04-08

Technologies: GitLab Community Edition (CE), GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab has fixed a security flaw in its Community and Enterprise editions that could allow a logged-in user to trigger unauthorized internal server functions. By sending specially crafted messages through the platform's real-time communication system (WebSockets), an attacker could potentially access sensitive data or interfere with system operations. This issue affects self-managed GitLab instances, and administrators are advised to upgrade to the latest patched versions immediately.

Technical details

An improper access control vulnerability exists in GitLab CE/EE's implementation of ActionCable WebSockets. The root cause is that the `action_methods` allowlist in ActionCable includes all public methods on any superclass between the specific channel and `ActionCable::Channel::Base`. Because `ApplicationCable::Channel` includes modules like `Gitlab::Auth::AuthFinders`, an authenticated attacker can use the `perform` action to invoke approximately 48 different public methods (such as `find_user_from_warden` or `clear_memoization`) with user-supplied arguments. This can lead to unauthorized information disclosure or unintended state changes. The issue is resolved in versions 18.10.3, 18.9.5, and 18.8.9.

Affected products

  • GitLab GitLab Community Edition (CE) 16.9.6 to 18.8.8, 18.9.0 to 18.9.4, 18.10.0 to 18.10.2
  • GitLab GitLab Enterprise Edition (EE) 16.9.6 to 18.8.8, 18.9.0 to 18.9.4, 18.10.0 to 18.10.2

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: patched: Fixed in 18.10.3, 18.9.5, 18.8.9

References

Related threats