CVE-2026-1094: GitLab

Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an authenticated developer to hide specially crafted file changes from the WebUI.

Affected products

  • GitLab GitLab: from 18.8.0, before 18.8.4 (fixed in 18.8.4)

Published 2026-02-11. Last modified 2026-06-17.