
PEACH
Un cadre d’isolation des locataires
CVE-2026-9204 is a Server-Side Request Forgery (SSRF) vulnerability in GitLab CE/EE that allows authenticated users to read arbitrary files from the Gitaly server and access internal network resources during repository import operations. It affects all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2. The vulnerability was published on June 11, 2026, and has been remediated by GitLab. It carries a CVSS v3.1 base score of 6.5 (Medium) per NVD, or 5.3 (Moderate) per the GitHub Advisory Database (GitHub Advisory, GitLab Patch Release).
The root cause is insufficient validation of secondary URLs during the repository import process (CWE-918: Server-Side Request Forgery). An authenticated attacker with low privileges can supply a crafted secondary URL during a repository import operation, causing the Gitaly server to fetch resources from unintended internal or external locations. This enables reading arbitrary files accessible to the Gitaly server process and probing internal network resources. Exploitation requires only low privileges and no user interaction, but certain unspecified conditions must be met (GitHub Advisory, GitLab Patch Release).
Successful exploitation results in a high confidentiality impact — an authenticated attacker can read arbitrary files from the Gitaly server (potentially including sensitive configuration files, credentials, or repository data) and access internal network resources that would otherwise be unreachable. There is no integrity or availability impact. The ability to probe internal network resources also introduces risk of lateral movement within the infrastructure hosting the GitLab instance (GitHub Advisory, GitLab Patch Release).
file:///etc/passwd, an internal metadata endpoint, or an internal network service) that bypasses GitLab's URL validation.file:// scheme requests.169.254.169.254), or unexpected external hosts initiated during repository import operations.GitLab has released patched versions addressing this vulnerability: 18.10.8, 18.11.5, and 19.0.2. All users running affected versions (18.10.x before 18.10.8, 18.11.x before 18.11.5, or 19.0.x before 19.0.2) should upgrade immediately. As an additional defense-in-depth measure, implement network segmentation to restrict Gitaly server access to only trusted sources, and validate or block secondary URLs used during repository import at the network perimeter (GitLab Patch Release, GitHub Advisory).
Security news outlets including GBHackers and CyberPress covered the GitLab patch release, noting multiple vulnerabilities addressed in the June 2026 patch cycle. The vulnerability was also highlighted in broader coverage of GitLab's security posture. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-9204 has been identified beyond standard vulnerability aggregator postings.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."