CVE-2026-5173Patch(gitlab / gitlab)

LOWCVSS 8.5 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch gitlab gitlab systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-749

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 13 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 10 signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-04-09); latest day: 2
  • 13 total mentions across 6 days

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline13 mentions / 6d
01223Mentions · 2026-04-08: 2Mentions · 2026-04-09: 3Mentions · 2026-04-10: 3Mentions · 2026-04-11: 1Mentions · 2026-04-13: 2Mentions · 2026-04-16: 2PoC Mentioned / Linked · 2026-04-13: 1Patch / Workaround · 2026-04-08: 2Patch / Workaround · 2026-04-09: 3Patch / Workaround · 2026-04-10: 3Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 3Technical Details · 2026-04-10: 2Technical Details · 2026-04-11: 1Technical Details · 2026-04-13: 2Technical Details · 2026-04-16: 104-0804-0904-1004-1104-1304-16
Signal classification3 categories
Patch
1076.9%
Disclosure
215.4%
PoC
17.7%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-04-082
Patch2
2026-04-093
Patch3
2026-04-103
Patch3
2026-04-111
Disclosure1
2026-04-132
Patch1PoC1
2026-04-162
Disclosure1Patch1
Full discourse13 posts
  • FOFA@fofabot
    Patch

    ⚠️⚠️ CVE-2026-5173 (CVSS 8.5): GitLab patched an authenticated WebSocket access-control flaw. 🔗https://en.fofa.info/result?qbase64=YXBwPSJHaXRMYWIi 🎯362.2K+ GitLab surfaces indexed. FOFA Query: app="GitLab" 🔖https://securityonline.info/gitlab-security-patch-18-10-3-websocket-graphql-vulnerabilities/ https://t.co/ozurKROdDF

    Post summary

    The tweet announces GitLab’s patch for CVE‑2026‑5173, outlining an authenticated WebSocket access‑control flaw and linking to a vendor advisory, but provides no PoC, exploit code, or evidence of active exploitation.

    018035102.7K
    14.3K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-5173, CVE-2026-1092, CVE-2025-12664 and other: Vulnerabilities in GitLab CE and EE, up to 8.5 rating 🔥 Several vulnerabilities in GitLab could compromise code integrity and allow an unauthenticated user to cause denial of service. 👉https://nt.ls/QGxUF

    Post summary

    The post announces several GitLab CE/EE vulnerabilities, noting potential DoS impacts and code integrity concerns, but does not provide exploitation details, patch information, or evidence of active attacks.

    03045972
    7.5K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos GitLab ❗ CVE-2026-5173 ❗ CVE-2026-1092 ❗ CVE-2025-12664 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-gitlab-9/ https://t.co/D1iCzaS7Aq

    Post summary

    The tweet announces three CVEs (CVE-2026-5173, CVE-2026-1092, CVE-2025-12664) affecting GitLab products and directs readers to a CERT page for more information, but it does not provide technical details, exploits, or mitigation guidance.

    00030449
    6.7K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 تحديثات GitLab لمعالجة ثغرات تسمح بهجمات Dos وحقن التعليمات البرمجية أصدرت GitLab تحديثات أمنية عاجلة (الإصدارات 18.10.3، 18.9.5، 18.8.9) لمعالجة ثغرات تستهدف منصات Community Edition و Enterprise Edition. تستغل هذه الثغرات، مثل CVE-2026-5173 وCVE-2026-1092، هجمات حرمان من الخدمة (DoS) وحقن التعليمات البرمجية، بالإضافة إلى تنفيذ أوامر من جانب الخادم وتسريب المعلومات. يتأثر بذلك استقرار النظام وأمن بيانات المستخدمين في البيئات المستضافة ذاتيًا. يُنصح مدراء الأنظمة بالترقية الفورية إلى الإصدارات المحدثة لتحييد المخاطر المحتملة. 🔗 للمزيد: https://cybersecuritynews.com/gitlab-patches-multiple-vulnerabilities-2/

    Post summary

    GitLab released urgent security updates (18.10.3, 18.9.5, 18.8.9) to fix CVE-2026-5173 and CVE-2026-1092, which allow DoS, code injection, remote command execution, and information leakage. Updating to these versions mitigates the identified risks.

    00030290
    256 followersView on X
  • iototsecnews@iototsecnews
    Patch

    GitLab の脆弱性 CVE-2026-5173 などが FIX:コード・インジェクションと DoS 攻撃の恐れ https://iototsecnews.jp/2026/04/09/gitlab-patches-multiple-vulnerabilities-that-enables-dos-and-code-injection-attacks/ 今回の緊急アップデートの背景にあるのは、GitLab の内部システムにおけるアクセス制御の不備や、外部からの入力データに対する検証の甘さです。最も深刻な CVE-2026-5173 は、WebSocket 通信の不適切な制御に起因し、認証済みのユーザーに対してサーバ上での不正なコマンド実行を許すものです。また、不正な JSON データや大量のクエリによりシステムを停止させる DoS 攻撃の脆弱性 CVE-2026-1092/CVE-2025-12664 も、入力に対するチェック不足の問題です。ご利用のチームは、ご注意ください。 #CVE202512664 #CVE20259484 #CVE20261092 #CVE20261101 #CVE20261403 #CVE20261516 #CVE20261752 #CVE20262104 #CVE20262619 #CVE20264332 #CVE20264916 #CVE20265173 #GitLab #Vulnerability

    Post summary

    GitLab has issued an emergency patch for several critical vulnerabilities, including CVE-2026-5173 that allows authenticated command execution via WebSocket and CVE-2026-1092/CVE-2025-12664 that enable DoS attacks through malformed JSON. Teams should update immediately.

    01000130
    484 followersView on X
  • dbugs@ptdbugs
    Patch

    Exposed Dangerous Method or Function in GitLab CVE: CVE-2026-5173 PT ID: PT-2026-31548 Vendor: Gitlab Product: GitLab CVSS: 8.5 Credits: This vulnerability has been discovered internally by GitLab team member Simon Tomlinson Description: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-5173 • https://gitlab.com/gitlab-org/gitlab/-/work_items/588959 • https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/ #dbugs_vuln

    Post summary

    The post announces GitLab’s patch for CVE‑2026‑5173, briefly describes the vulnerability’s improper access control flaw, but furnishes no evidence of exploitation, PoC, or false claims.

    00001111
    788 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-5173 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an… https://www.cve.org/CVERecord?id=CVE-2026-5173

    Post summary

    The text confirms that GitLab has released a remediation for CVE‑2026‑5173 and provides affected version ranges, but it offers no PoC, exploit code, or evidence of active exploitation.

    00010195
    57.0K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: GitLab released a patch fixing multiple vulnerabilities in CE/EE, including high-severity CVE-2026-5173 (CVSS 8.5) exposing a dangerous method. https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/ #Patch #Patch #Patch

    Post summary

    GitLab has released a patch that addresses CVE‑2026‑5173, a high‑severity vulnerability with a CVSS score of 8.5.

    00000173
    7.2K followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼#GitLab: un Proof of Concept (#PoC) per lo sfruttamento della vulnerabilità CVE-2026-5173 risulta disponibile in rete Rischio: 🔴 Tipologia: 🔸 Security Restrictions Bypass 🔸 Denial of Service 🔗https://www.acn.gov.it/portale/en/w/risolte-vulnerabilita-su-gitlab-ce/ee-12 🔄 Aggiornamenti d… https://t.co/K8AjseXMas

    Post summary

    The post announces that a Proof of Concept for CVE‑2026‑5173, which involves a security restrictions bypass and denial‑of‑service, is publicly available, but it does not mention active exploitation or patches.

    0000071
    609 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    GitLab releases critical updates for CE and EE editions fixing 12 vulnerabilities, including high-severity websocket flaw CVE-2026-5173. Patched versions 18.10.3, 18.9.5, and 18.8.9 address DoS and data risks. #GitLabUpdate #WebsocketFlaw #DevOps https://ift.tt/Fys7VmI

    Post summary

    GitLab released critical updates for CE and EE editions, including a fix for CVE-2026-5173, with patched versions 18.10.3, 18.9.5, and 18.8.9.

    00000132
    3.9K followersView on X
  • Wes DeVault, CISSP@wvipersg
    Patch

    GitLab Security Update Fixes High-Severity CVE-2026-5173, 11 Other Flaws https://ift.tt/Fr80z2e

    Post summary

    GitLab released a security update that fixes the high‑severity CVE‑2026‑5173 and additional flaws, confirming a patch is available.

    0000044
    273 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-5173: HIGH] GitLab fixed a security issue in GitLab CE/EE versions 16.9.6 to 18.10.3. This bug could enable authenticated users to access unintended server-side methods via websockets.#cve,CVE-2026-5173,#cybersecurity https://cvefind.com/CVE-2026-5173

    Post summary

    The text reports the release of a security patch for CVE‑2026‑5173, describing its high‑severity nature and how it affects authenticated users via websockets.

    0000049
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-5173 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an… https://www.cve.org/CVERecord?id=CVE-2026-5173 ----- Traducción: CVE-2026-5173 Git… http://infoflow.cloud`

    Post summary

    GitLab announced remediation of CVE-2026-5173 for multiple CE/EE versions; no PoC, exploit, or active exploitation details are provided.

    0000036
    67 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---

Explore more