git: df4d3f7eddc7 - main - security/vuxml: document Gitlab vulnerabilities

Matthias Fechner <[email protected]>
Newsgroups gmane.os.freebsd.devel.cvs.ports
Message-ID <[email protected]>
The branch main has been updated by mfechner:

URL: https://cgit.FreeBSD.org/ports/commit/?id=df4d3f7eddc75c36ad47574bbd72feae0101c4bf

commit df4d3f7eddc75c36ad47574bbd72feae0101c4bf
Author:     Matthias Fechner <[email protected]>
AuthorDate: 2026-08-18 05:07:57 +0000
Commit:     Matthias Fechner <[email protected]>
CommitDate: 2026-08-18 05:07:57 +0000

    security/vuxml: document Gitlab vulnerabilities
---
 security/vuxml/vuln/2026.xml | 31 +++++++++++++++++++++++++++++++
 1 file changed, 31 insertions(+)

diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml
index 8027cd117825..2de485ad0f11 100644
--- a/security/vuxml/vuln/2026.xml
+++ b/security/vuxml/vuln/2026.xml
@@ -1,3 +1,34 @@
+  <vuln vid="3a65fb7e-9ac2-11f1-bdc8-2cf05da270f3">
+    <topic>Gitlab -- Vulnerabilities</topic>
+    <affects>
+<package>
+	<name>gitlab-ce</name>
+	<name>gitlab-ee</name>
+	<range><ge>19.2.0</ge><lt>19.2.4</lt></range>
+	<range><ge>19.1.0</ge><lt>19.1.6</lt></range>
+	<range><ge>18.11.10</ge><lt>19.0.8</lt></range>
+</package>
+    </affects>
+    <description>
+	<body xmlns="http://www.w3.org/1999/xhtml">
+	<p>Gitlab reports:</p>
+	<blockquote cite="https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/?nav=19.2.4">
+	  <p>Code Injection issue via GraphQL directive impacts GitLab CE/EE</p>
+	  <p>Cross-Site Request Forgery issue in GraphQL multiplex query handler impacts GitLab CE/EE</p>
+	</blockquote>
+	</body>
+    </description>
+    <references>
+      <cvename>CVE-2026-19478</cvename>
+      <cvename>CVE-2026-19650</cvename>
+      <url>https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/?nav=19.2.4</url>
+    </references>
+    <dates>
+      <discovery>2026-08-17</discovery>
+      <entry>2026-08-18</entry>
+    </dates>
+  </vuln>
+
   <vuln vid="2f3568eb-999e-11f1-a655-3497f65b111b">
     <topic>gitea -- Multiple vulnerabilities</topic>
     <affects>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.