Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2864 articles · 109203 vulns · 38/41 feeds (7d)
← Back to list
8.5
CVE-2026-5173EXPLOITEDPATCHED
gitlab · gitlab

Exposed Dangerous Method or Function in GitLab

Description

A vulnerability marked as critical has been reported in GitLab Community Edition and Enterprise Edition up to 18.8.8/18.9.4/18.10.2. This affects an unknown part of the component Websocket Connection Handler. This manipulation causes exposed dangerous routine. The identification of this vulnerability is CVE-2026-5173. It is possible to initiate the attack remotely.

Affected Products

VendorProductVersions
gitlabgitlab16.9.6, 18.9, 18.10, 18.8.8, 18.9.4, 18.10.2

References

  • https://gitlab.com/gitlab-org/gitlab/-/work_items/588959
  • https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/

Related News (1 articles)

Tier C
VulDB2h ago
CVE-2026-5173 | GitLab Community Edition/Enterprise Edition up to 18.8.8/18.9.4/18.10.2 Websocket Connection routine
→ No new info (linked only)
CVSS 3.18.5 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
18.8.918.9.518.10.3
CWECWE-749
PublishedApr 8, 2026
Last enriched2h agov2
Trending Score50
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-1516EXP
Improper Control of Generation of Code ('Code Injection') in GitLab
Trending: 50
CRITICALCVE-2025-12664EXP
Improper Validation of Specified Quantity in Input in GitLab
Trending: 49
HIGHCVE-2026-2104EXP
Authorization Bypass Through User-Controlled Key in GitLab
Trending: 47
HIGHCVE-2025-9484
Missing Authorization in GitLab
Trending: 27
HIGHCVE-2026-1101
Improper Validation of Specified Quantity in Input in GitLab
Trending: 27

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 8, 2026
Discovered by ZDM
Apr 8, 2026
Actively Exploited
Apr 8, 2026
Patch Available
Apr 8, 2026
Updated: description, severity, affectedVersions, activelyExploited
Apr 9, 2026

Version History

v2
Last enriched 2h ago
v2Tier C2h ago

Updated severity to CRITICAL, added new affected versions, and corrected exploit availability status.

descriptionseverityaffectedVersionsactivelyExploited
via VulDB
v13h ago

Initial creation