Junglewise Threat Intelligence

CVE-2026-7471: GitLab Enterprise Edition SSRF in virtual registry upstream

CVE-2026-7471 · Severity: low · CVSS 3.5 · Published 2026-05-14

Technologies: GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab Enterprise Edition, a platform for software development and collaboration, contains a security flaw in its virtual registry component. An authenticated user who controls an external registry source can trick the GitLab server into making unauthorized requests to internal systems. This could allow an attacker to probe private internal network services that are not intended to be accessible from the outside.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in GitLab EE's virtual registry upstream handling. The issue stems from improper validation of upstream configurations, which allows an authenticated attacker with control over a virtual registry upstream to force the GitLab server to initiate network requests to internal hosts. The attack requires network access and low-level authentication. While the impact is limited to information disclosure (CVSS C:L), it bypasses intended network segmentation. Patches are available in versions 18.9.7, 18.10.6, and 18.11.3.

Affected products

  • GitLab GitLab Enterprise Edition 18.8 to < 18.9.7, 18.10 to < 18.10.6, 18.11 to < 18.11.3

Timeline

  • 2026-05-13: patched: GitLab released versions 18.11.3, 18.10.6, and 18.9.7
  • 2026-05-14: disclosed: Public disclosure of CVE-2026-7471

References

Related threats