GitLab CE/EE Private Debugging Symbols Download Vulnerability Due to Improper Access Control

Vulnerability

A vulnerability exists in GitLab CE/EE versions 16.7 prior to 18.9.7, 18.10 prior to 18.10.6, and 18.11 prior to 18.11.3. This vulnerability could have allowed an unauthenticated user to download private debugging symbols from restricted projects, due to inadequate access control measures.

Impact

Exploitation of this vulnerability could lead to unauthorized access to private debugging symbols, potentially exposing sensitive information or project details.

Remediation

Users can upgrade to GitLab versions 18.11.3, 18.10.6, or 18.9.7 to address this vulnerability.

Added: May 14, 2026, 6:51 AM
Updated: May 14, 2026, 6:51 AM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
8.7
remediation
7.7
relevance
8.3
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.