An IDOR exists in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.
gitlab gitlab