Page MenuHomePhabricator

GitLab Security Release: 18.7.1, 18.6.3, 18.5.5
Closed, ResolvedPublicSecurity

Description

Blog post: https://about.gitlab.com/releases/2026/01/07/patch-release-gitlab-18-7-1-released/

Includes the following fixes:

Stored Cross-site Scripting issue in GitLab Flavored Markdown placeholders impacts GitLab CE/EE 	High
Cross-site scripting issue in Web IDE impacts GitLab CE/EE 	High
Missing Authorization issue in Duo Workflows API impacts GitLab EE 	High
Denial of Service issue in import functionality impacts GitLab CE/EE 	Medium
Missing Authorization issue in AI GraphQL mutation impacts GitLab EE 	Medium
Insufficient Access Control Granularity issue in GraphQL runnerUpdate mutation impacts GitLab CE/EE 	Medium
Information Disclosure issue in Mermaid diagram rendering impacts GitLab CE/EE 	Low

docs
[version specific upgrade docs]()
[deprecations]()
[changelog]()

Test instance:

  • gitlab-1001.devtools.eqiad1.wikimedia.cloud
  • gitlab-runner-1007.devtools.eqiad1.wikimedia.cloud
  • gitlab-runner-1008.devtools.eqiad1.wikimedia.cloud

Replicas:

  • gitlab1003.wikimedia.org
  • gitlab2002.wikimedia.org

Production:

  • gitlab1004.wikimedia.org
  • Trusted runners
  • Shared runners
  • Cloud runners MR opened

Details

Risk Rating
Medium
Author Affiliation
WMF Technology
Related Changes in Gerrit:
Related Changes in GitLab:
TitleReferenceAuthorSource BranchDest Branch
gitlab-runner: bump image version to alpine-v18.5.0repos/releng/gitlab-cloud-runner!543jeltogitlab-runner-18-5main
Customize query in GitLab

Event Timeline

Jelto triaged this task as High priority.

I updated gitlab-ce package to 18.5.5-ce.0 and gitlab-runner to 18.5.0-1, I'll proceed with updating the test hosts in a moment.

Test hosts done, I'll continue with the replicas.

Jelto updated the task description. (Show Details)

All instances updated, I'll resolve the task.

sbassett moved this task from Incoming to Our Part Is Done on the Security-Team board.
sbassett changed Author Affiliation from N/A to WMF Technology.
sbassett changed the visibility from "Custom Policy" to "Public (No Login Required)".
sbassett changed the edit policy from "Custom Policy" to "All Users".
sbassett changed Risk Rating from N/A to Medium.

Mentioned in SAL (#wikimedia-releng) [2026-01-08T15:55:09Z] <dancy> Upgrading gitlab-runner to v18.5.0 on gitlab-cloud-runners. (T414053)