GitLab Patches Multiple CE/EE Vulnerabilities
CERT-FR advisory details multiple GitLab CE/EE vulnerabilities enabling data exposure, denial of service, and XSS attacks.
CERT-FR has issued an advisory covering multiple vulnerabilities discovered in GitLab Community Edition (CE) and Enterprise Edition (EE). Affected versions include 19.1.x prior to 19.1.3, 19.2.x prior to 19.2.1, and all versions prior to 19.0.5. The vulnerabilities collectively allow an attacker to compromise data confidentiality, bypass security policies, cause remote denial of service, and perform indirect remote code injection via cross-site scripting (XSS).
Thirteen CVEs are referenced in this advisory, though the article does not provide individual descriptions or CVSS scores for each. GitLab published a patch release bulletin on July 29, 2026, addressing these issues in version 19.2.1. Administrators running affected GitLab CE/EE instances are advised to apply the vendor's patches promptly, referencing the official GitLab security bulletin for remediation details.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0946
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free