CVE-2026-15216

Summary

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled data rendered in pagination controls by an analytics dashboard component.

Affected Software

VendorProductVersion RangeStatus
GitLabGitLab18.2 < 19.0.6affected
GitLabGitLab19.1 < 19.1.4affected
GitLabGitLab19.2 < 19.2.2affected

Weaknesses

  • CWE-79: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

References