Gitlab reports: Cross-site Scripting issue in Mermaid sandbox impacts GitLab CE/EE Denial of Service issue in container registry impacts GitLab CE/EE Denial of Service issue in Jira events endpoint impacts GitLab CE/EE Regular Expression Denial of Service issue in GitLab merge requests impacts GitLab CE/EE Missing rate limit in Bitbucket Server importer impacts GitLab CE/EE Denial of Service issue in CI trigger API impacts GitLab CE/EE Denial of Service issue in token decoder impacts GitLab CE/EE Improper Access Control issue in Conan package registry impacts GitLab EE Access Control issue in CI job mutation impacts GitLab CE/EE
https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-released/