Improper Data Sanitization in GitLab Products
CVE-2026-78252

8.2HIGH

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-78252?

A vulnerability has been identified in GitLab CE/EE that allows an authenticated user to potentially exploit improper sanitization of user-controlled data within the Markdown JSON table renderer. This can lead to targeted users unknowingly performing unintended state-changing HTTP requests. The issue affects all versions starting from 15.3 up to but not including 19.1.8, 19.2 up to but not including 19.2.6, and 19.3 up to but not including 19.3.2. Users are advised to upgrade to the latest version to mitigate the risk.

Affected Version(s)

GitLab 15.3 < 19.1.8

GitLab 19.2 < 19.2.6

GitLab 19.3 < 19.3.2

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [a_m_a_m](https://hackerone.com/a_m_a_m) for reporting this vulnerability through our HackerOne bug bounty program
.