What is CVE-2026-16553?
This vulnerability in GitLab EE could allow sensitive information disclosure to an unintended host due to improper handling of upstream requests. It affects versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1. Immediate update to the patched versions is recommended.
Azərbaycanca: Bu boşluq GitLab EE-nin müəyyən versiyalarında, yuxarı axın sorğularının düzgün idarə olunmaması səbəbindən həssas məlumatların gözlənilməz hosta sızmasına yol aça bilər. Məsələ 18.8-dən 19.0.5-ə, 19.1-dən 19.1.3-ə və 19.2-dən 19.2.1-ə qədər olan bütün versiyalara təsir edir. Təhlükəsizlik üçün dərhal göstərilən yamaqlanmış versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: GitLab
FAQ2
Which versions of GitLab EE are affected by CVE-2026-16553?
This vulnerability affects GitLab EE versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1.
Why can CVE-2026-16553 lead to sensitive information disclosure?
Because improper handling of upstream requests could allow information to be sent to an unintended host.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.