# GitLab Patches Multiple CE/EE Vulnerabilities

Published: 2026-07-30 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/4e1368df-6a87-5a7e-beea-020ac6bab2c4/gitlab-patches-multiple-ce-ee-vulnerabilities

> CERT-FR advisory details multiple GitLab CE/EE vulnerabilities enabling data exposure, denial of service, and XSS attacks.

CERT-FR has issued an advisory covering multiple vulnerabilities discovered in GitLab Community Edition (CE) and Enterprise Edition (EE). Affected versions include 19.1.x prior to 19.1.3, 19.2.x prior to 19.2.1, and all versions prior to 19.0.5. The vulnerabilities collectively allow an attacker to compromise data confidentiality, bypass security policies, cause remote denial of service, and perform indirect remote code injection via cross-site scripting (XSS).

Thirteen CVEs are referenced in this advisory, though the article does not provide individual descriptions or CVSS scores for each. GitLab published a patch release bulletin on July 29, 2026, addressing these issues in version 19.2.1. Administrators running affected GitLab CE/EE instances are advised to apply the vendor's patches promptly, referencing the official GitLab security bulletin for remediation details.

## Mentioned in this report

- Vulnerabilities: CVE-2025-14562, CVE-2026-12436, CVE-2026-13113, CVE-2026-14341, CVE-2026-14351, CVE-2026-15077, CVE-2026-15831, CVE-2026-15975, CVE-2026-16553, CVE-2026-3093, CVE-2026-4672, CVE-2026-6267, CVE-2026-6336

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0946

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4e1368df-6a87-5a7e-beea-020ac6bab2c4/gitlab-patches-multiple-ce-ee-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
