CVE-2026-78252: GitLab

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user could have induced a targeted user to perform unintended state-changing HTTP requests due to improper sanitization of user-controlled data in the Markdown JSON table renderer.

Affected products

  • GitLab GitLab: from 15.3.0, before 19.1.8 (fixed in 19.1.8); from 19.2.0, before 19.2.6 (fixed in 19.2.6); from 19.3.0, before 19.3.2 (fixed in 19.3.2)

Published 2026-09-16. Last modified 2026-09-28.