Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Gitlab" — 19 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105640] Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses return…
Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which Plane matches directly to th…
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-90970] GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of t…
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command…
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad alta en GitLab CE/EE permite ejecución de JavaScript malicioso (CVE-2026-84739)
GitLab ha remediado una vulnerabilidad de puntuación CVSS 8.7 que afecta versiones 13.11 a 19.4.1 en Community Edition y Enterprise Edition. Un usuario autenticado podría ejecutar código JavaScript arbitrario en la sesión del navegador de otro usuario mediante sanitización deficiente en el visor de diferencias de solicitudes de fusión. Esta vulnerabilidad de escalada de privilegios impacta directamente sistemas DevOps y repositorios de código fuente en infraestructuras altas de empresas mexicanas y latinoamericanas.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-89078] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 …
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-92470] GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 bef…
GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to access sensitive CI/CD variable values from debug-mode job traces through the Duo AI troubleshooting feature due to missing authorization checks.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-93577] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 …
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-86059] Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organizatio…
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git provider access can retrieve plaintext provider credentials through github.one, gitlab.one, gitea.one, and bitbucket.one because those protected procedures return full provider rows without applying getAccessibleGitProviderIds or an organization check. The application.one route…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-78252] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 …
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user could have induced a targeted user to perform unintended state-changing HTTP requests due to improper sanitization of user-controlled data in the Markdown JSON table renderer.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-79708] GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 bef…
GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to execute a policy test pipeline on projects within their group and access protected CI/CD variables restricted to higher-privileged roles, due to insufficient scope…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-1168] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.…
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation limits in the GraphQL complexity calculation logic.
M Alto vulnerabilidad
16/09/2026
[CVE-2025-14871] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.…
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation limits in the GraphQL complexity calculation logic.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-61560] `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the S…
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the server's local filesystem via an unsanitized `file_path` parameter and uploads them to a GitLab project. Combined, any unauthenticated network-reachable attacker…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-61559] `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and …
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls made within that request. The server validates that the value is a well-formed URL (`…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-61568] `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expos…
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled `Host` and `Origin`. The server accepts those headers and reaches the MCP in…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-88765] GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before …
GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a specially crafted Git project export to overflow the Unicode conversion buffer used in Advanced Search indexing.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-13210] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 …
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to access CI/CD variables outside their intended environment scope due to improper input validation in the environment scope pattern matcher.
M Crítico vulnerabilidad
12/09/2026
Vulnerabilidad crítica en GitLab EE permite acceso a credenciales sensibles (CVE-2026-87719)
GitLab Enterprise Edition presenta una falla de seguridad en versiones 18.3 a 19.3.1 que permite a usuarios autenticados con acceso a Duo Chat obtener configuraciones de Advanced Search y credenciales sensibles mediante argumentos GraphQL especialmente diseñados. La vulnerabilidad afecta principalmente a empresas LATAM que utilizan GitLab EE para almacenar código crítico y secretos de aplicaciones. Con puntuación CVSS 9.9, esta falla requiere atención inmediata en infraestructuras de DevOps.
M Crítico vulnerabilidad
12/09/2026
Vulnerabilidad crítica en GitLab CE/EE permite lectura no autenticada de archivos arbitrarios
GitLab ha remediado una vulnerabilidad que afecta versiones 18.7, 19.1 antes de 19.1.8, 19.2 antes de 19.2.6 y 19.3 antes de 19.3.2. Un usuario no autenticado puede leer archivos arbitrarios del servidor GitLab explotando falta de confinamiento de rutas y validación de autenticación en la API de commits del repositorio. Este riesgo es crítico (CVSS 10.0) para empresas en LATAM que usan GitLab para control de versión y CI/CD.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88880] Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagi…
Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.