CVE-2020-26413: GitLab
Medium severity, CVSS 5.3. EPSS: 34.9% chance of exploitation in the next 30 days.
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.
Affected products
- GitLab GitLab: from 13.4.0, before 13.6.2 (fixed in 13.6.2)
Published 2020-12-11. Last modified 2026-06-17.