CVE-2026-84739 | GitLab up to 19.2.6/19.3.2/19.4.0 Merge Request Diff Viewer cross site scripting
A vulnerability, which was classified as problematic, was found in GitLab up to 19.2.6/19.3.2/19.4.0. The affected element is an unknown function of the component Merge Request Diff Viewer. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-84739. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.VulDB Recent EntriesRead More