GitLab patches multiple CE/EE vulnerabilities
GitLab fixed multiple flaws in CE/EE including XSS, security bypass, and data confidentiality issues across versions before 19.0.4, 19.1.2, and 18.11.7.
CERT-FR issued an advisory covering multiple vulnerabilities in GitLab Community Edition and Enterprise Edition. The flaws span three impact categories: confidentiality breaches, security policy bypass, and remote indirect code injection (cross-site scripting). Affected versions include 19.0.x prior to 19.0.4, 19.1.x prior to 19.1.2, and all versions prior to 18.11.7.
Eight CVEs are referenced in the advisory (CVE-2025-12506, CVE-2026-11827, CVE-2026-13151, CVE-2026-13320, CVE-2026-6352, CVE-2026-6896, CVE-2026-7492, CVE-2026-8472), though the bulletin does not provide per-CVE technical detail. GitLab published a corresponding patch release bulletin on July 8, 2026, directing administrators to upgrade to the fixed versions. No evidence of active exploitation is mentioned in the advisory.
Given the lack of confirmed in-the-wild exploitation and the routine nature of a vendor patch cycle, this is a standard advisory requiring administrators to apply updates promptly, particularly given GitLab's widespread use in software development and CI/CD pipelines across many sectors.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0850
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free