CVE-2026-12053: GitLab

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows.

Affected products

  • GitLab GitLab: version 19.1.0 only

Published 2026-06-25. Last modified 2026-06-26.