CVE-2026-4868: Gitlab Improper Scan Grouping By Scanner Only

Ingested vulnerability reports are grouped by scanner alone, leading to accidental dropping or improper resolution of findings that share a scanner but have different scan types (e.g., SBOM vs Dependency Scanning).

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Ruby
greprules fetch cve-2026-4868-gitlab-improper-scan-grouping-by-scanner-only --engine opengrep

Description

Ingested vulnerability reports are grouped by scanner alone, leading to accidental dropping or improper resolution of findings that share a scanner but have different scan types (e.g., SBOM vs Dependency Scanning).