CVE-2026-82669: Klaussilveira Gitlist
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
A vulnerability was detected in klaussilveira GitList 2.0.0. Affected by this issue is the function SimpleXMLElement of the file src/SCM/System/Git/CommandLine.php of the component XML Parsing. Performing a manipulation results in denial of service. The attack is possible to be carried out remotely. The exploit is now public and may be used. Upgrading to version 3.0.0-beta can resolve this issue. The patch is named f67609d52c1812fa8a7ed80eae5e795cfd72115f. It is advisable to upgrade the affected component.
Affected products
- Klaussilveira Gitlist: version 2.0.0 only
Published 2026-08-31. Last modified 2026-09-02.