Use of Incorrectly-Resolved Name or Reference in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-1230
Published: March 12, 2026
Vulnerability identifier: #VU123959
CSH Severity: Medium
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N]
CVE-ID: CVE-2026-1230
CWE-ID: CWE-706
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to incorrect validation of branch references in repository download. A remote user can cause repository downloads to contain different code than displayed in the web interface.
Affected software
Gitlab Community Edition
GitLab Enterprise Edition
GitLab Enterprise Edition
How to mitigate CVE-2026-1230
Install updates from vendor's website.
Gitlab Community Edition - addressed in versions 18.7.6, 18.8.6, 18.9.2
GitLab Enterprise Edition - addressed in versions 18.7.6, 18.8.6, 18.9.2
GitLab Enterprise Edition - addressed in versions 18.7.6, 18.8.6, 18.9.2