PoC Index

CVE-2026-3074

MEDIUM 4.3EPSS 0.2%

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to download private debugging symbols from inaccessible projects due to improper access control.

CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.20% chance of exploitation in the next 30 days, 10th percentile
Published
2026-05-14

Proof-of-concept exploits (1)

References

Related