dbugs[verified]@ptdbugsPatch
GitLab disclosed and patched CVE‑2026‑2370, which allowed authenticated users with minimal workspace permissions to obtain installation credentials and impersonate the GitLab app; the patch is available for all affected versions.
Gray Hats@the_yellow_fallPatch
GitLab released a patch for CVE-2026-2370 and CVE-2026-3857, which could enable app impersonation and AI token leaks, and users are urged to upgrade to specific 18.x releases.
CVEarity@CVEarityGeneral
The tweet announces CVE‑2026‑2370 with a severity score of 8.1 but provides no additional technical details, PoC, or exploit information, categorizing it as a general vulnerability alert with moderate confidence.
CosmicBytez@CosmicBytezPatch
The advisory points to CVE-2026-2370, labeling it a credential impersonation issue in GitLab Jira Connect, but offers no direct patch details or exploit evidence.
CVE@CVEnewPatch
The post announces that GitLab has issued a remediation for CVE‑2026‑2370, specifying affected product versions, but it does not provide technical details, a PoC, or evidence of exploitation.
The Hacker Wire@TheHackerWirePatch
The notice informs users that GitLab has remediated CVE‑2026‑2370, outlining the vulnerable version ranges and confirming a patch has been applied.
CERT-PY@CERTpyDisclosure
The advisory announces three GitLab CVEs and directs readers to external links for more information, but no technical or mitigation details are provided.