<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:55:00 +0000</lastBuildDate>
    <item>
      <title>BIT-gitlab-2026-4398 — Authorization Bypass Through User-Controlled Key in GitLab</title>
      <link>https://cve.radiocsirt.org/vuln/bit-gitlab-2026-4398</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from namespaces they were not authorized to access to their own project, due to missing namespace validation on self-managed instances.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from namespaces they were not authorized to access to their own project, due to missing namespace validation on self-managed instances.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-gitlab-2026-4398</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1086 — De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1086</link>
      <description>certfr-2026-avi-1086</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1086</guid>
    </item>
    <item>
      <title>EUVD-2026-361127</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-361127</link>
      <description>EUVD-2026-361127</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-361127</guid>
    </item>
    <item>
      <title>fkie_cve-2026-4398</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4398</link>
      <description>&lt;p&gt;GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from namespaces they were not authorized to access to their own project, due to missing namespace validation on self-managed instances.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from namespaces they were not authorized to access to their own project, due to missing namespace validation on self-managed instances.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-4398</guid>
    </item>
    <item>
      <title>GHSA-hpxp-rx7c-457j</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hpxp-rx7c-457j</link>
      <description>&lt;p&gt;Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hpxp-rx7c-457j</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3029 — GitLab: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3029</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Daten zu manipulieren und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Daten zu manipulieren und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3029</guid>
    </item>
  </channel>
</rss>
