GitLab Patches XSS and Unauthenticated DoS Flaws in Self-Managed CE and EE
GitLab issued emergency security updates for self-managed Community Edition and Enterprise Edition instances to fix multiple high-severity vulnerabilities, including several cross-site scripting (XSS) flaws and unauthenticated denial-of-service (DoS) issues. The XSS bugs could allow attackers to run malicious JavaScript in users’ browsers, potentially leading to session hijacking, token theft, and repository manipulation, while the DoS flaws could disrupt CI/CD pipelines and broader workflow operations.
The affected products are GitLab CE and EE versions earlier than 18.11.3, 18.10.6, and 18.9.7, and administrators were urged to review GitLab’s release guidance and upgrade immediately to those patched versions. GitLab said its cloud-hosted platforms had already been remediated, while self-hosted operators were warned that single-node upgrades require downtime because of database migrations, whereas multi-node deployments can follow standard zero-downtime upgrade procedures.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
3 events from the most recent confirmed update back to the earliest known activity.
Canadian Centre for Cyber Security issues GitLab advisory
On 2026-05-14, the Canadian Centre for Cyber Security published advisory AV26-467 warning about the GitLab CE and EE vulnerabilities. It directed users and administrators to review GitLab's release information and apply updates to versions 18.11.3, 18.10.6, or 18.9.7.
GitLab discloses XSS and unauthenticated DoS impact details
GitLab said the patched flaws included multiple high-severity cross-site scripting issues that could enable malicious JavaScript execution, session hijacking, token theft, and repository manipulation, as well as unauthenticated denial-of-service issues that could disrupt CI/CD and workflow operations. GitLab also noted that its cloud-hosted platforms had already been patched and urged self-managed administrators to upgrade immediately.
GitLab releases security updates for CE and EE vulnerabilities
On 2026-05-13, GitLab published a security advisory and emergency patch releases for vulnerabilities affecting self-managed GitLab Community Edition and Enterprise Edition instances. The remediation versions were 18.11.3, 18.10.6, and 18.9.7 for affected installations running earlier releases.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
3 references tracked. Mallory keeps watching after this page renders.
GitLab security advisory (AV26-467) - Canadian Centre for Cyber Security
cyber.gc.ca
Open sourceCritical GitLab Vulnerabilities Enables XSS and Unauthenticated DoS Attacks
cybersecuritynews.com
Open sourceGitLab Patch Release: 18.11.3, 18.10.6, 18.9.7 | GitLab Docs
docs.gitlab.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


