GitLab CE/EE Package Upload Bypass Vulnerability for Developer Role Users

Vulnerability

A vulnerability exists in GitLab CE/EE versions 17.6 prior to 18.9.7, 18.10 prior to 18.10.6, and 18.11 prior to 18.11.3. This issue allows authenticated users with developer-role permissions to bypass PyPI package protection rules and upload restricted packages. The vulnerability arises from improper authorization checks that fail to enforce package upload restrictions for users with the specified permissions.

Impact

Exploitation of this vulnerability could lead to unauthorized package uploads, bypassing established protection rules and potentially allowing the distribution of malicious or harmful packages within the GitLab environment.

Remediation

Users can upgrade to GitLab versions 18.11.3, 18.10.6, or 18.9.7 to address this vulnerability.

Added: May 14, 2026, 6:53 AM
Updated: May 14, 2026, 6:53 AM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
0.6
exploitability
6.6
remediation
7.7
relevance
8.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.