Gitlab · Gitlab · CVE-2026-78252
**Name of the Vulnerable Software and Affected Versions**
GitLab CE/EE versions 15.3 through 19.1.7
GitLab CE/EE versions 19.2 through 19.2.5
GitLab CE/EE versions 19.3 through 19.3.1
**Description**
An authenticated user can induce a targeted user to perform unintended state-changing HTTP requests. This occurs due to improper sanitization of user-controlled data within the Markdown JSON table renderer.
**Recommendations**
Update GitLab CE/EE versions 15.3 through 19.1.7 to version 19.1.8.
Update GitLab CE/EE versions 19.2 through 19.2.5 to version 19.2.6.
Update GitLab CE/EE versions 19.3 through 19.3.1 to version 19.3.2.