Dev · Security
GitLab patches 11 flaws across three release lines
GitLab’s 19.4.1, 19.3.3 and 19.2.7 updates resolve 11 vulnerabilities in the Community and Enterprise editions.
Two critical flaws let authenticated users reach code execution through crafted regular expressions in CI/CD configurations. GitLab reports no attacks so far and urges operators of self-managed installations to update promptly. GitLab.com is already protected.
GitLab has released versions 19.4.1, 19.3.3 and 19.2.7 for Community Edition and Enterprise Edition. The updates close 11 vulnerabilities and target self-managed installations. GitLab.com already runs a secured version, while GitLab Dedicated customers have no update task.
Two vulnerabilities are rated critical: CVE-2026-89078 and CVE-2026-93577. In both cases, an authenticated user can submit a specially crafted regular expression through a CI/CD configuration and, under certain conditions, execute arbitrary code on the GitLab server. The first issue results from a memory error while parsing the expression. The second involves an integer overflow during compilation. No attacks have been reported.
CVE-2026-84739 and CVE-2026-92470 carry a high severity rating. The first allows an authenticated attacker to run JavaScript in a victim’s browser through an XSS attack involving the display of merge request changes. The second can expose protected CI/CD variable values in Enterprise Edition and is linked to GitLab Duo AI job analysis.
The remaining seven flaws include permission-checking errors and access to confidential data. One of them can make CI/CD job logs readable without authentication. Version 19.2.7 also restores the documentation page for Slack notifications.
Readers’ Forum
No contributions yet — open the debate.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.