CVE-2018-19856: GitLab

High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.

GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API.

Affected products

  • GitLab GitLab: before 11.3.12 (fixed in 11.3.12); from 11.4.0, before 11.4.10 (fixed in 11.4.10); from 11.5.0, before 11.5.3 (fixed in 11.5.3)

Published 2019-03-26. Last modified 2026-06-17.