CVE-2026-5262: Gitlab Incomplete Scanner Grouping

Grouping vulnerabilities only by scanner without report_type can lead to erroneous vulnerability resolution when different report types share the same scanner.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Ruby
greprules fetch cve-2026-5262-gitlab-incomplete-scanner-grouping --engine opengrep

Description

Grouping vulnerabilities only by scanner without report_type can lead to erroneous vulnerability resolution when different report types share the same scanner.