CVE-2026-12635
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to make requests to internal network resources through mirror synchronization due to improper URL validation.
Scoring
- Severity
- NONE
- CVSS base score
- 0
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N
- EPSS probability
- 0.25%
- CWE
- CWE-350
- Published
- 2026-06-25
- Last modified
- 2026-06-25
Affected products
- GitLab GitLab
- GitLab GitLab
- GitLab GitLab
Weakness type
Related vulnerabilities
- CVE-2026-55526 — PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
- CVE-2026-56709 — Grav before 3.9.2 Host Header Injection via sendInvitationEmail
- CVE-2026-75514 — BunkerWeb: rDNS bypass via missing forward-confirmation (FCrDNS) in blacklist, greylist, and antibot
- CVE-2026-63118 — MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
- CVE-2026-55391 — datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
- CVE-2026-46611 — Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack
- CVE-2026-42559 — RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport
- CVE-2026-6874 — ericc-ch copilot-api Header token dns rebinding