CVE•Published 2026-04-08•Modified 2026-07-24•1 article on news•5 live references•NVD data
CVE-2026-5173Gitlab · Gitlab
Vulnerability data via NVD (ingested)
CVSS v3.1
8.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
EPSS percentile
35
Exploit Prediction Scoring System · top 65% of all CVEs
Weaknesses (CWE)
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control.
Timeline
Published 2026-04-08
Modified 2026-07-24
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2026-5173Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product
product:"Gitlab Gitlab"All exposed Gitlab Gitlab instances — cross-reference with the CVE's affected-version range.
Shodan · banner/body mention
http.html:"Gitlab"HTTP body or banner mentions "Gitlab" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-5173Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-5173Censys host search filtered to this CVE id.
grep.app
CVE-2026-5173Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-5173GitHub code search for direct mentions.
Google dork
"CVE-2026-5173" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (8)
CVE-2026-51738 repos
nomi-sec/PoC-in-GitHubunknown
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
QQ3221197721/cloudai-fusionGo
Mafifrizi/ARESPython
ARES - authorized red-team engagement automation with dashboard, campaign scope, module orchestration, OPSEC controls, encrypted vault, and reporting.
MontrealAI/AGI-Alpha-Agent-v0Python
META‑AGENTIC α‑AGI 👁️✨ — Mission 🎯 End‑to‑end: Identify 🔍 → Out‑Learn 📚 → Out‑Think 🧠 → Out‑Design 🎨 → Out‑Strategise ♟️ → Out‑Execute ⚡
arkeep-io/arkeepGo
Manage backups across all your servers from a single dashboard.
CycloneDX/sbom-utilityGo
Utility that provides an API platform for validating, querying and managing BOM data
eldarshiraliyev/BugScannerPython
🐛 Advanced web vulnerability scanner with 5-rule false-positive reduction, WAF evasion, and modern HTML reports
Intrafere/MOTO-Autonomous-ASIPython
MOTO is an automated theorem generator for science. It's a creative novelty-seeking researcher with autonomous Lean 4 proof generation. Run for days at a time once pressing start -…