Server-Side Request Forgery (SSRF) in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-9204
Published: June 11, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to server-side request forgery in Gitaly repository import when validating secondary URLs during repository import. A remote user can supply crafted secondary URLs to disclose sensitive information.
The issue may allow reading arbitrary files from the Gitaly server and accessing internal network resources during repository import.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2026-9204
GitLab Enterprise Edition - addressed in versions 18.10.8, 18.11.5, 19.0.2