CVE-2026-1516Patch(gitlab / gitlab)

LOWCVSS 5.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gitlab gitlab systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of users viewing the report via specially crafted content.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-08); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-08: 2Mentions · 2026-04-09: 1Patch / Workaround · 2026-04-08: 2Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 104-0804-09
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-082
Patch2
2026-04-091
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Patch

    CVE-2026-1516 GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports … https://www.cve.org/CVERecord?id=CVE-2026-1516

    Post summary

    GitLab announces that CVE‑2026‑1516 has been remediated; users should upgrade to at least version 18.8.9, 18.9.5, or 18.10.3 depending on their release line.

    00010249
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1516 Authenticated IP Address Leak in GitLab EE Code Quality Reports https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1516

    Post summary

    The post is a concise disclosure of an authenticated IP address leak in GitLab EE Code Quality Reports, providing no additional technical or exploit details.

    0000065
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-1516 GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports … https://www.cve.org/CVERecord?id=CVE-2026-1516 ----- Traducción: CVE-2026-1516 Git… http://infoflow.cloud`

    Post summary

    GitLab has released a remediation for CVE-2026-1516 affecting several EE releases. The post does not mention exploitation activity or a PoC.

    0000030
    67 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---

Explore more