GitLabCVE-2026-16553
GitLab: information disclosure
Medium5.4CVE-2026-16553 · Published Jul 29, 2026 · updated Aug 3, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of upstream requests in virtual registries.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GitLab Product | >= 18.8, < 19.0.5 | 19.0.5 |
| >= 19.1, < 19.1.3 | 19.1.3 | |
| >= 19.2, < 19.2.1 | 19.2.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-522
More GitLab advisories
All GitLab| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 29 | GitLab: information disclosure | High8.5 | 19.0.5+2 more |
| Jul 29 | GitLab: missing authorization | Medium5.3 | 19.0.5+2 more |
| Jul 29 | GitLab: cross-site scripting | Medium4.7 | 19.0.5+2 more |
| Jul 29 | GitLab: improper access control | Medium4.3 | 19.0.5+2 more |
| Jul 29 | GitLab: denial of service | High7.5 | 19.0.5+2 more |
| Jul 29 | GitLab: improper authorization | Medium4.9 | 19.0.5+2 more |