CVE-2020-26413: GitLab

Medium severity, CVSS 5.3. EPSS: 34.9% chance of exploitation in the next 30 days.

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

Affected products

  • GitLab GitLab: from 13.4.0, before 13.6.2 (fixed in 13.6.2)

Published 2020-12-11. Last modified 2026-06-17.