Back to search

Gitlab

Gitlab

See the latest tracked release, confirm when it was published, and subscribe for update emails.

Current version
Last checked: 2026-09-04

19.3.1

Release date
August 26, 2026
Security status
21 high-severity CVEs tracked in the last 90 days. Current version not affected.

Source

GitLab Docs

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
19.3.1 2026-08-26 Release Notes
19.2.4 2026-08-17 Release Notes
19.2.2 2026-08-12 Release Notes
19.2.1 2026-07-29 Release Notes
19.2.0 2026-07-16 Release Notes
19.1.2 2026-07-08 Release Notes
19.1.1 2026-06-24 Release Notes
19.1.0 2026-06-18 Release Notes
19.0.2 2026-06-10 Release Notes
19.0.1 2026-05-27 Release Notes
19.0.0 2026-05-21 Release Notes
19.4.0 1-01-01 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-18252 HIGH (7.3) 2026-08-26 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.

Affected versions
  • From (including) 18.9 - Up to (excluding) 19.1.7
  • From (including) 19.2 - Up to (excluding) 19.2.5
Show 1 more
  • From (including) 19.3 - Up to (excluding) 19.3.1
CVE-2026-10053 HIGH (8.5) 2026-08-23 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.

Affected versions
  • From (including) 18.8 - Up to (excluding) 19.0.6
  • From (including) 19.1 - Up to (excluding) 19.1.4
Show 1 more
  • From (including) 19.2 - Up to (excluding) 19.2.2
CVE-2026-19650 HIGH (7.1) 2026-08-17 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.

Affected versions
  • From (including) 18.2 - Up to (excluding) 18.11.11
  • From (including) 19.0 - Up to (excluding) 19.0.8
Show 2 more
  • From (including) 19.1 - Up to (excluding) 19.1.6
  • From (including) 19.2 - Up to (excluding) 19.2.4
CVE-2026-19478 CRITICAL (9.4) 2026-08-17 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Affected versions
  • From (including) 18.2 - Up to (excluding) 18.11.11
  • From (including) 19.0 - Up to (excluding) 19.0.8
Show 2 more
  • From (including) 19.1 - Up to (excluding) 19.1.6
  • From (including) 19.2 - Up to (excluding) 19.2.4
CVE-2026-15217 HIGH (8.7) 2026-08-12 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled values rendered in table cell content by an analytics dashboard component.

Affected versions
  • From (including) 18.2 - Up to (excluding) 19.0.6
  • From (including) 19.1 - Up to (excluding) 19.1.4
Show 1 more
  • From (including) 19.2 - Up to (excluding) 19.2.2
CVE-2026-15216 HIGH (8.7) 2026-08-12 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled data rendered in pagination controls by an analytics dashboard component.

Affected versions
  • From (including) 18.2 - Up to (excluding) 19.0.6
  • From (including) 19.1 - Up to (excluding) 19.1.4
Show 1 more
  • From (including) 19.2 - Up to (excluding) 19.2.2
CVE-2026-16494 HIGH (7.1) 2026-08-12 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization checks on a project update endpoint.

Affected versions
  • From (including) 19.1 - Up to (excluding) 19.1.4
  • From (including) 19.2 - Up to (excluding) 19.2.2
CVE-2026-19228 HIGH (8.5) 2026-08-12 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of identity information supplied in requests.

Affected versions
  • From (including) 19.1 - Up to (excluding) 19.1.4
  • From (including) 19.2 - Up to (excluding) 19.2.2
CVE-2026-15423 HIGH (8.5) 2026-08-12 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute CI/CD pipelines on a protected branch without the required push permissions due to improper authorization in pipeline reference validation.

Affected versions
  • From (including) 19.0 - Up to (excluding) 19.0.6
  • From (including) 19.1 - Up to (excluding) 19.1.4
Show 1 more
  • From (including) 19.2 - Up to (excluding) 19.2.2
CVE-2026-16627 HIGH (7.7) 2026-08-12 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate privileges due to improper sanitization of HTML content rendered in a CI job modal.

Affected versions
  • From (including) 19.2 - Up to (excluding) 19.2.2
CVE-2026-6267 HIGH (8.5) 2026-07-29 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.

Affected versions
  • From (including) 10.1.0 - Up to (excluding) 19.0.5
  • From (including) 19.1 - Up to (excluding) 19.1.3
Show 1 more
  • From (including) 19.2 - Up to (excluding) 19.2.1
CVE-2026-12436 HIGH (8.4) 2026-07-29 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes when processing pipeline schedule inputs.

Affected versions
  • From (including) 18.0 - Up to (excluding) 19.0.5
  • From (including) 19.1 - Up to (excluding) 19.1.3
Show 1 more
  • From (including) 19.2 - Up to (excluding) 19.2.1
CVE-2026-15975 HIGH (7.5) 2026-07-29 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions.

Affected versions
  • From (including) 11.8 - Up to (excluding) 19.0.5
  • From (including) 19.1 - Up to (excluding) 19.1.3
Show 1 more
  • From (including) 19.2 - Up to (excluding) 19.2.1
CVE-2026-6896 HIGH (8.7) 2026-07-08 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.

Affected versions
  • From (including) 13.11 - Up to (excluding) 18.11.7
  • From (including) 19.0 - Up to (excluding) 19.0.4
Show 1 more
  • From (including) 19.1 - Up to (excluding) 19.1.2
CVE-2026-13320 HIGH (7.3) 2026-07-08 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.

Affected versions
  • From (including) 15.7 - Up to (excluding) 18.11.7
  • From (including) 19.0 - Up to (excluding) 19.0.4
Show 1 more
  • From (including) 19.1 - Up to (excluding) 19.1.2
CVE-2026-10086 HIGH (8.7) 2026-06-25 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in the context of another user's session, due to improper sanitization of user-supplied input.

Affected versions
  • From (including) 16.4 - Up to (excluding) 18.11.6
  • From (including) 19.0 - Up to (excluding) 19.0.3
Show 1 more
  • From (including) 19.1 - Up to (excluding) 19.1.1
CVE-2026-10712 HIGH (8.0) 2026-06-25 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions.

Affected versions
  • From (including) 18.10 - Up to (excluding) 18.11.6
  • From (including) 19.0 - Up to (excluding) 19.0.3
Show 1 more
  • From (including) 19.1 - Up to (excluding) 19.1.1
CVE-2026-12053 HIGH (8.6) 2026-06-25 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows.

Affected versions
  • From (including) 19.1 - Up to (excluding) 19.1.1
CVE-2026-7250 HIGH (7.5) 2026-06-11 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsing middleware.

Affected versions
  • From (including) 12.10 - Up to (excluding) 18.10.8
  • From (including) 18.11 - Up to (excluding) 18.11.5
Show 1 more
  • From (including) 19.0 - Up to (excluding) 19.0.2
CVE-2026-8589 HIGH (7.3) 2026-06-11 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to add unauthorized email addresses to a targeted user's account due to improper sanitization of user-supplied input in certain group setting fields.

Affected versions
  • From (including) 13.1.4 - Up to (excluding) 18.10.8
  • From (including) 18.11 - Up to (excluding) 18.11.5
Show 1 more
  • From (including) 19.0 - Up to (excluding) 19.0.2
CVE-2026-10087 HIGH (8.7) 2026-06-11 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code on behalf of a targeted user due to improper input sanitization in the Analytics Dashboard.

Affected versions
  • From (including) 17.1 - Up to (excluding) 18.10.8
  • From (including) 18.11 - Up to (excluding) 18.11.5
Show 1 more
  • From (including) 19.0 - Up to (excluding) 19.0.2