CVE-2026-5173 | GitLab Community Edition/Enterprise Edition up to 18.8.8/18.9.4/18.10.2 Websocket Connection routine (EUVD-2026-20802)
A vulnerability marked as critical has been reported in GitLab Community Edition and Enterprise Edition up to 18.8.8/18.9.4/18.10.2. This affects an unknown part of the component Websocket Connection Handler. This manipulation causes exposed dangerous routine.
The identification of this vulnerability is CVE-2026-5173. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.