CVE-2026-14351CWE-1230

CVE-2026-14351

Medium · published July 30, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
21.7
In the wild
Unconfirmed
What it is

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to view the title of a confidential issue through a publicly accessible merge request due to improper authorization checks.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00295 · 21.7th percentile
Weakness
CWE-1230 · Exposure of Sensitive Information Through Metadata
Published
2026-07-30T00:17Z
Affected products (6)
ProductVersionsFixed in
gitlab/gitlab≥ 8.8.0, < 19.0.519.0.5
gitlab/gitlab≥ 8.8.0, < 19.0.519.0.5
gitlab/gitlab≥ 19.1.0, < 19.1.319.1.3
gitlab/gitlab≥ 19.1.0, < 19.1.319.1.3
gitlab/gitlaball versions
gitlab/gitlaball versions
References (3)
EPSS history
Timeline
  • 29 JUL 19:00Z
    Exposure of Sensitive Information Through Metadata in GitLab
    cvelistv5