CVE-2026-3857Patch(gitlab / gitlab)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gitlab gitlab systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to execute arbitrary GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-25); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
gitlab

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-25: 4Mentions · 2026-03-26: 1Patch / Workaround · 2026-03-25: 3Technical Details · 2026-03-25: 303-2503-26
Signal classification3 categories
Patch
360.0%
General
120.0%
Disclosure
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-254
General1Patch3
2026-03-261
Disclosure1
Full discourse5 posts
  • Gray Hats@the_yellow_fall
    Patch

    GitLab fixes critical flaws (CVE-2026-2370, CVE-2026-3857) allowing app impersonation and AI leaks. Upgrade to 18.10.1, 18.9.3, or 18.8.7 now to stay safe. #GitLab #CyberSecurity #InfoSec #PatchAlert #DevSecOps #AIPrivacy #TechNews #DevOps #SecurityUpdate https://securityonline.info/gitlab-critical-security-update-impersonation-ai-token-leak/ https://t.co/VqhFcVnkDz

    Post summary

    The tweet announces critical GitLab CVEs and urges users to patch to specific versions to mitigate app impersonation and AI leak risks.

    1901961.5K
    10.9K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos GitLab ❗ CVE-2026-3857 ❗ CVE-2026-2995 ❗ CVE-2026-2370 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-gitlab-8/ https://t.co/FWg1Jvl80o

    Post summary

    The tweet lists three CVE identifiers affecting GitLab products but does not include technical details, exploits, or mitigation steps.

    00000110
    6.6K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-3857 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an … https://www.cve.org/CVERecord?id=CVE-2026-3857

    Post summary

    GitLab announced a remediation for CVE-2026-3857 across several major versions, highlighting that the issue could have allowed a serious vulnerability, but no active exploitation or PoC is reported.

    00000156
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Patch

    🟠 CVE-2026-3857 - High GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to ... https://www.thehackerwire.com/vulnerability/CVE-2026-3857/ https://t.co/2T1mH9ZgXm

    Post summary

    GitLab has released a patch for CVE-2026-3857, addressing the vulnerability across multiple versions of GitLab CE/EE.

    0000044
    145 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3857 - Cross-Site Request Forgery (CSRF) in GitLab Intel Report: https://ift.tt/uNH2P09

    Post summary

    An alert reports the CVE‑2026‑3857 CSRF vulnerability in GitLab, providing only basic technical details without any proof of exploit, active exploitation, patch, or mitigations.

    0000038
    286 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---
Appgitlabgitlab18.10.0--
Appgitlabgitlab18.10.0--

Explore more