CVE-2026-84739 | GitLab up to 19.2.6/19.3.2/19.4.0 Merge Request Diff Viewer cross site scripting

SecurityVulns

A vulnerability, which was classified as problematic, was found in GitLab up to 19.2.6/19.3.2/19.4.0. The affected element is an unknown function of the component Merge Request Diff Viewer. The manipulation results in cross site scripting.

This vulnerability is reported as CVE-2026-84739. The attack can be launched remotely. No exploit exists.

You should upgrade the affected component.VulDB Recent EntriesRead More