CVE-2026-6515: GitLab

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed a user to use invalidated or incorrectly scoped credentials to access Virtual Registries under certain conditions.

Affected products

  • GitLab GitLab: from 18.2.0, before 18.9.6 (fixed in 18.9.6); from 18.10.0, before 18.10.4 (fixed in 18.10.4); version 18.11.0 only

Published 2026-04-22. Last modified 2026-06-17.