References https://cve.imfht.com/detail/CVE-2026-1660 https://cve.imfht.com/detail/CVE-2026-1101 https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-10-3-released/ https://www.sentinelone.com/vulnerability-database/cve-2026-1725/ https://avd.aliyun.com/detail?id=AVD-2023-0121 https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-11-1-released/ https://zeropath.com/blog/cve-2026-1092-gitlab-terraform-state-lock-dos https://www.nsfocus.net/vulndb/121195
Related VulnerabilitiesPoCCVE-2026-85706: GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File ReadGitLab CE/EE /api/graphql 未授权访问漏洞(CVE-2026-19478)PoCCVE-2026-19478: GitLab CE/EE - GraphQL @gl_introduced Arbitrary Method InvocationPoCCVE-2021-22175: GitLab CI Lint API - Server-Side Request ForgeryGitLab GitLab CE/EE 权限管理不当漏洞GitLab CE/EE GraphQL 身份验证缺陷漏洞gitlab-api-user-enum: GitLab - User Information Disclosure Via Open APIPoCCVE-2024-45409: GitLab - SAML Authentication BypassPoCCVE-2025-25291: GitLab - SAML Authentication BypassPoCCVE-2019-6793: GitLab Enterprise Edition - Server-Side Request ForgeryPoCCVE-2020-2096: Jenkins Gitlab Hook <=1.4.2 - Cross-Site ScriptingPoCCVE-2020-26413: Gitlab CE/EE 13.4 - 13.6.2 - Information DisclosurePoCCVE-2021-22205: GitLab CE/EE - Remote Code Execution