Back to search

Gitlab

Gitlab

See the latest tracked release, confirm when it was published, and subscribe for update emails.

Current version
Last checked: 2026-06-03

19.0.1

Release date
May 27, 2026
Security status
25 high-severity CVEs tracked in the last 90 days. Current version not affected.

Source

GitLab Docs

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
19.0.1 2026-05-27 Release Notes
19.0.0 2026-05-21 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-4868 HIGH (8.2) 2026-05-27 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authenticated user to cause specific Duo AI workflows to run under another user's identity due to improper user identity resolution when triggering Duo AI workflow runners.

Affected versions
  • From (including) 18.8.0 - Up to (excluding) 18.10.7
  • From (including) 18.11.0 - Up to (excluding) 18.11.4
CVE-2026-7481 HIGH (8.7) 2026-05-14 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to execute arbitrary JavaScript in other users' browsers due to improper input sanitization.

Affected versions
  • From (including) 16.4.0 - Up to (excluding) 18.9.7
  • From (including) 18.10.0 - Up to (excluding) 18.10.6
Show 1 more
  • From (including) 18.11.0 - Up to (excluding) 18.11.3
CVE-2026-7377 HIGH (8.7) 2026-05-14 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization.

Affected versions
  • From (including) 18.7.0 - Up to (excluding) 18.9.7
  • From (including) 18.10.0 - Up to (excluding) 18.10.6
Show 1 more
  • From (including) 18.11.0 - Up to (excluding) 18.11.3
CVE-2026-6073 HIGH (8.7) 2026-05-14 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to execute arbitrary JavaScript in other users' browsers due to improper input sanitization.

Affected versions
  • From (including) 18.7.0 - Up to (excluding) 18.9.7
  • From (including) 18.10.0 - Up to (excluding) 18.10.6
Show 1 more
  • From (including) 18.11.0 - Up to (excluding) 18.11.3
CVE-2026-1659 HIGH (7.5) 2026-05-14 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted requests due to insufficient input validation.

Affected versions
  • From (including) 9.0.0 - Up to (excluding) 18.9.7
  • From (including) 18.10.0 - Up to (excluding) 18.10.6
Show 1 more
  • From (including) 18.11.0 - Up to (excluding) 18.11.3
CVE-2026-1322 HIGH (8.1) 2026-05-14 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with a read_api scoped OAuth application to create issues and add comments to issues in private projects due to improper authorization.

Affected versions
  • From (including) 16.0.0 - Up to (excluding) 18.9.7
  • From (including) 18.10.0 - Up to (excluding) 18.10.6
Show 1 more
  • From (including) 18.11.0 - Up to (excluding) 18.11.3
CVE-2026-1184 HIGH (7.5) 2026-05-14 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by uploading a specially crafted file due to improper validation.

Affected versions
  • From (including) 11.9.0 - Up to (excluding) 18.9.7
  • From (including) 18.10.0 - Up to (excluding) 18.10.6
Show 1 more
  • From (including) 18.11.0 - Up to (excluding) 18.11.3
CVE-2025-14870 HIGH (7.5) 2026-05-14 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted JSON payloads due to insufficient input validation.

Affected versions
  • From (including) 18.5.0 - Up to (excluding) 18.9.7
  • From (including) 18.10.0 - Up to (excluding) 18.10.6
Show 1 more
  • From (including) 18.11.0 - Up to (excluding) 18.11.3
CVE-2025-14869 HIGH (7.5) 2026-05-14 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted payloads on certain API endpoints.

Affected versions
  • From (including) 18.5.0 - Up to (excluding) 18.9.7
  • From (including) 18.10.0 - Up to (excluding) 18.10.6
Show 1 more
  • From (including) 18.11.0 - Up to (excluding) 18.11.3
CVE-2026-5816 HIGH (8.1) 2026-04-22 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions.

Affected versions
  • From (including) 18.10.0 - Up to (excluding) 18.10.4
CVE-2026-5262 HIGH (8.0) 2026-04-22 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation.

Affected versions
  • From (including) 16.1.0 - Up to (excluding) 18.9.6
  • From (including) 18.10.0 - Up to (excluding) 18.10.4
CVE-2026-4922 HIGH (8.1) 2026-04-22 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.

Affected versions
  • From (including) 17.0.0 - Up to (excluding) 18.9.6
  • From (including) 18.10.0 - Up to (excluding) 18.10.4
CVE-2026-5173 HIGH (8.5) 2026-04-08 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control.

Affected versions
  • From (including) 16.9.6 - Up to (excluding) 18.8.9
  • From (including) 18.9.0 - Up to (excluding) 18.9.5
Show 1 more
  • From (including) 18.10.0 - Up to (excluding) 18.10.3
CVE-2026-1092 HIGH (7.5) 2026-04-08 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service due to improper input validation of JSON payloads.

Affected versions
  • From (including) 12.10.0 - Up to (excluding) 18.8.9
  • From (including) 18.9.0 - Up to (excluding) 18.9.5
Show 1 more
  • From (including) 18.10.0 - Up to (excluding) 18.10.3
CVE-2025-12664 HIGH (7.5) 2026-04-08 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.

Affected versions
  • From (including) 13.0.0 - Up to (excluding) 18.8.9
  • From (including) 18.9.0 - Up to (excluding) 18.9.5
Show 1 more
  • From (including) 18.10.0 - Up to (excluding) 18.10.3
CVE-2026-2370 HIGH (8.8) 2026-03-30 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with minimal workspace permissions to obtain installation credentials and impersonate the GitLab app due to improper authorization checks.

Affected versions
  • From (including) 14.3.0 - Up to (excluding) 18.8.7
  • From (including) 18.9.0 - Up to (excluding) 18.9.3
CVE-2026-3988 HIGH (7.5) 2026-03-25 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to cause a denial of service by making the GitLab instance unresponsive due to improper input validation in GraphQL request processing.

Affected versions
  • From (including) 18.5.0 - Up to (excluding) 18.8.7
  • From (including) 18.9.0 - Up to (excluding) 18.9.3
CVE-2026-3857 HIGH (8.8) 2026-03-25 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to execute arbitrary GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.

Affected versions
  • From (including) 17.10.0 - Up to (excluding) 18.8.7
  • From (including) 18.9.0 - Up to (excluding) 18.9.3
CVE-2026-2995 HIGH (7.7) 2026-03-25 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to add email addresses to targeted user accounts due to improper sanitization of HTML content.

Affected versions
  • From (including) 15.4.0 - Up to (excluding) 18.8.7
  • From (including) 18.9.0 - Up to (excluding) 18.9.3
CVE-2026-2745 HIGH (8.1) 2026-03-25 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to bypass WebAuthn two-factor authentication and gain unauthorized access to user accounts due to inconsistent input validation in the authentication process.

Affected versions
  • From (including) 7.11.0 - Up to (excluding) 18.8.7
  • From (including) 18.9.0 - Up to (excluding) 18.9.3
CVE-2026-1724 HIGH (7.5) 2026-03-25 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to access API tokens of self-hosted AI models due to improper access control.

Affected versions
  • From (including) 18.5.0 - Up to (excluding) 18.8.7
  • From (including) 18.9.0 - Up to (excluding) 18.9.3
CVE-2026-1090 HIGH (8.7) 2026-03-11 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inject JavaScript in a browser due to improper sanitization of placeholder content in markdown processing.

Affected versions
  • From (including) 10.6.0 - Up to (excluding) 18.7.6
  • From (including) 18.8.0 - Up to (excluding) 18.8.6
Show 1 more
  • From (including) 18.9.0 - Up to (excluding) 18.9.2
CVE-2026-1069 HIGH (7.5) 2026-03-11 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by sending specially crafted GraphQL requests due to uncontrolled recursion under certain circumstances.

Affected versions
  • From (including) 18.9.0 - Up to (excluding) 18.9.2
CVE-2025-14513 HIGH (7.5) 2026-03-11 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially crafted JSON payloads in the protected branches API.

Affected versions
  • From (including) 16.11.0 - Up to (excluding) 18.7.6
  • From (including) 18.8.0 - Up to (excluding) 18.8.6
Show 1 more
  • From (including) 18.9.0 - Up to (excluding) 18.9.2
CVE-2025-13929 HIGH (7.5) 2026-03-11 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by issuing specially crafted requests to repository archive endpoints under certain conditions.

Affected versions
  • From (including) 10.0.0 - Up to (excluding) 18.7.6
  • From (including) 18.8.0 - Up to (excluding) 18.8.6
Show 1 more
  • From (including) 18.9.0 - Up to (excluding) 18.9.2