CVE-2026-34749: Payload has a CSRF Protection Bypass in Authentication Flow
A Cross-Site Request Forgery (CSRF) vulnerability existed in the authentication flow. Under certain conditions, the configured CSRF protection could be bypassed, allowing cross-site requests to be made.
Consumers are affected if ALL of these are true:
- Payload version < v3.79.1
serverURLis configured
References
Code Behaviors & Features
Detect and mitigate CVE-2026-34749 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →