CVE-2026-1090Patch(gitlab / gitlab)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gitlab gitlab systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inject JavaScript in a browser due to improper sanitization of placeholder content in markdown processing.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 5 signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-11); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-03-11: 2Mentions · 2026-03-12: 2Mentions · 2026-03-15: 1Mentions · 2026-03-16: 1Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-12: 2Patch / Workaround · 2026-03-15: 1Technical Details · 2026-03-11: 2Technical Details · 2026-03-12: 2Technical Details · 2026-03-15: 103-1103-1203-1503-16
Signal classification2 categories
Patch
583.3%
General
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-112
Patch2
2026-03-122
Patch2
2026-03-151
Patch1
2026-03-161
General1
Full discourse6 posts
  • CCB Alert@CCBalert
    Patch

    Warning: #Gitlab patched 15 vulnerabilities. The most critical one (#CVE-2026-1090, CVSSv3.1 8.7) could allow an authenticated attacker to inject JavaScript in a browser. Time to #Patch #Patch #Patch

    Post summary

    The tweet alerts users that Gitlab has patched 15 vulnerabilities, highlights CVE-2026-1090 with its severity score and impact, and urges immediate patching—no PoC, exploit code, or active exploitation is mentioned.

    01001280
    7.2K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    GitLab issues urgent security updates (18.9.2, 18.8.6, 18.7.6) fixing critical XSS (CVE-2026-1090) and DoS flaws. Patch self-managed instances today. #GitLab #CyberSecurity #CVE20261090 #InfoSec #DevSecOps #PatchAlert #XSS #Vulnerability #AppSec https://securityonline.info/code-red-gitlabs-latest-security-update-patches-high-severity-xss-and-api-dos-vulnerabilities/ https://t.co/GEMpH1BAGb

    Post summary

    The tweet warns of urgent security updates for GitLab, highlighting critical XSS and DoS flaws (CVE‑2026‑1090) and urges users to patch self‑managed instances immediately.

    00011319
    10.6K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos GitLab ❗ CVE-2026-1090 ❗ CVE-2026-1069 ❗ CVE-2025-13929 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-gitlab-7/ https://t.co/1cyXeet6qL

    Post summary

    The tweet lists three GitLab-related CVEs and directs readers to an external source for further information.

    00001206
    6.6K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-1090 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an aut… https://www.cve.org/CVERecord?id=CVE-2026-1090

    Post summary

    GitLab has issued a patch for CVE‑2026‑1090 across multiple major releases; no PoC, exploit, or active exploitation reports are mentioned.

    00000196
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-1090: HIGH] GitLab fixes critical security flaw in versions 10.6 to 18.9.2, which could enable JS injection by authenticated users via `markdown_placeholders`. #GitLab #cybersecurity#cve,CVE-2026-1090,#cybersecurity https://cvefind.com/CVE-2026-1090

    Post summary

    GitLab has released a patch for a critical JS injection flaw affecting versions 10.6–18.9.2, triggered by authenticated users through markdown placeholders.

    0000049
    602 followersView on X
  • The Hacker Wire@TheHackerWire
    Patch

    🟠 CVE-2026-1090 - High GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when th... https://www.thehackerwire.com/vulnerability/CVE-2026-1090/ https://t.co/ZBWDMiP002

    Post summary

    The post announces GitLab’s remediation of CVE-2026-1090, outlining affected releases and the potential impact on authenticated users, with no indication of active exploitation or a PoC.

    0000049
    134 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---

Explore more