From nobody Wed Mar 11 15:58:17 2026 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4fWFlg0y15z6VMr1 for ; Wed, 11 Mar 2026 15:58:23 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R12" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4fWFlg0Td6z3PNy for ; Wed, 11 Mar 2026 15:58:23 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1773244703; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=YiJpUDP1Z1fvf8hOd6YGX5DmhyFhpw5DOVI+FW2+haI=; b=JWsZxGPcoI/Ws3oEqXNTAb0NFXmFdMGty0fmKoi5JTUH86TpR8lBJoXggcFRyaGZnq3MFv rRz+7sM/noJ8jUtPENh0bw0iK0wOz434Rtl9EZgRssxAguCQ44Vn/afiTsLEwFrbdC11cj ar7WzUjnV1M/tdS23z4wsAGh5qIQoCUWX0o46VDGwFvjPQj90BPPhe/vdiTgnnXAYzRfXu T8HicLR6AxqBJIl+0kOgQpHlNH+gAYPDgEukby8jehu0gHtpQQfWXqBgXoGlgbr6qwxZdO noYBwixVx4r7JfG0o9Qk1ZhC91ZhgeV1A57GwYaEHoT+OzbD4FvfuCZOtte/AA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1773244703; a=rsa-sha256; cv=none; b=xPCTTjWBCRhnV3usRgh1UYQMKjnJus7s9oWQTcS6ByPD1E7Pa69uRlbkvWs8u+pzcep8ae GiyIHaiQYbjiCjmLQRPzl70oP1iIhocNCBeWgOi5UQwxYwsY6JnD4k23SLqme3KZCmJgfO EHS6dKP4gfKfa7Ap/EKCpS09OJKtoIBy4j8dnxdlejMigmSZRLZIhzfOMlASGAEj6jK66Q VRuHJbON9G/QH+aakmRqReae3eiCUeQBcPPzQbzHT8K3EzeDwibGvYZSsxJty7KrPKMDtz XnQJo6xAlnPa28ZIJBl8ubroQwPQLR9yzWTRtD2Y2EtFPXF/b2NhI9YX+trp6A== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1773244703; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=YiJpUDP1Z1fvf8hOd6YGX5DmhyFhpw5DOVI+FW2+haI=; b=ouOz1kjCE/H1Bgbzqf9uJ5usumaGUEwwX6JPIy6fNWyCyzA+vRVpaVXcIW0hhowVJxzOCC 4xAXXLihgd9bebRHbOKREMx6s9bKwQFsMOWNJl+kBJ/h06N+d0ZRDKywBO5HZr4gepncUq EVPructO0BaVQJ2iDs6fKVttnnE6tVPdr86gAhI9LChZSumCo2GnBPTKRmB73xfOtQXCNY qOFjU0XA8X1UqGP3EGL1BusDnZPKbms5J1RTKmonkDgqbOoRJ7Sb0uBwZr6SO4rMN1RhtR G/ZviaPQzwQGjdHv7hwBqLBJI/D0+D2X2KQlOtn5cepfX7K1clxcuxJTApyeiw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4fWFlf6pVBz155q for ; Wed, 11 Mar 2026 15:58:22 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 3d6f8 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Wed, 11 Mar 2026 15:58:17 +0000 To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Matthias Fechner Subject: git: dbc170015965 - main - security/vuxml: document gitlab vulnerabilities List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-all@freebsd.org Sender: owner-dev-commits-ports-all@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: mfechner X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: dbc17001596509677f1887ad07b10fbd1c8a141c Auto-Submitted: auto-generated Date: Wed, 11 Mar 2026 15:58:17 +0000 Message-Id: <69b19119.3d6f8.28890908@gitrepo.freebsd.org> The branch main has been updated by mfechner: URL: https://cgit.FreeBSD.org/ports/commit/?id=dbc17001596509677f1887ad07b10fbd1c8a141c commit dbc17001596509677f1887ad07b10fbd1c8a141c Author: Matthias Fechner AuthorDate: 2026-03-11 15:58:03 +0000 Commit: Matthias Fechner CommitDate: 2026-03-11 15:58:03 +0000 security/vuxml: document gitlab vulnerabilities --- security/vuxml/vuln/2026.xml | 55 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 55 insertions(+) diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml index 97db54cb2ef9..1375039d83e0 100644 --- a/security/vuxml/vuln/2026.xml +++ b/security/vuxml/vuln/2026.xml @@ -1,3 +1,58 @@ + + Gitlab -- vulnerabilities + + +gitlab-ce +gitlab-ee +18.9.018.9.2 +18.8.018.8.6 +1.0.018.7.6 + + + + +

Gitlab reports:

+
+

Cross-site Scripting issue in Markdown placeholder processing impacts GitLab CE/EE

+

Denial of Service issue in GraphQL API impacts GitLab CE/EE

+

Denial of Service issue in repository archive endpoint impacts GitLab CE/EE

+

Denial of Service issue in protected branches API impacts GitLab CE/EE

+

Denial of Service issue in webhook custom headers impacts GitLab CE/EE

+

Denial of Service issue in webhook endpoint impacts GitLab CE/EE

+

Improper Neutralization of CRLF Sequences issue impacts GitLab CE/EE

+

Improper Access Control issue in runners API impacts GitLab CE/EE

+

Improper Access Control issue in snippet rendering impacts GitLab CE/EE

+

Information Disclosure issue in inaccessible issues impacts GitLab CE/EE

+

Missing Authorization issue in Group Import impacts GitLab CE/EE

+

Incorrect Reference issue in repository download impacts GitLab CE/EE

+

Incorrect Authorization issue in Virtual Registry impacts GitLab EE

+

Improper Escaping of Output issue in Datadog integration impacts GitLab CE/EE

+
+ +
+ + CVE-2026-1090 + CVE-2026-1069 + CVE-2025-13929 + CVE-2025-14513 + CVE-2025-13690 + CVE-2025-12576 + CVE-2026-3848 + CVE-2025-12555 + CVE-2026-0602 + CVE-2026-1732 + CVE-2026-1663 + CVE-2026-1230 + CVE-2025-12704 + CVE-2025-12697 + https://about.gitlab.com/releases/2026/03/11/patch-release-gitlab-18-9-2-released/ + + + 2026-03-11 + 2026-03-11 + +
+ curl -- Multiple vulnerabilities