New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
GitLab Security Update: 2 Vulnerabilities Patched
GitLab pushed fixes for 2 security issues, one auth issue that could expose protected CI/CD vars to developer users, and another high severity XSS in the Markdown JSON table renderer.
No known exploitation so far. If running affected versions, update to 19.1.8 / 19.2.6 / 19.3.2.

Comments
https://www.cve.org/CVERecord?id=CVE-2026-79708
https://www.cve.org/CVERecord?id=CVE-2026-78252
Fuck
anything > gitlab
edit: i lied, bitbucket. fuck bitbucket
never found it a good idea to post security data to a version control.
My dyslexic self read that as Glibc and got very confused trying to figure out how an XSS could possibly apply to it.
Actual dyslexic or habitual?
The kind of dyslexic that misuses the term dyslexic as a synonym for misreading.
Hmm, literally me

I hunted a bit on GitLab a couple of months ago but was unlucky. Found 6 vulnerabilities in a week. 5 of those were duplicates - i.e. reported by others before me, in one case by just 2 hours. The 6th has passed preliminary review and is now pending. I am not hunting there anymore for now because their backlog is huge and they are very slow with updates and bounties.