GitLab patches multiple CE/EE vulnerabilities
ANSSI advisory details multiple GitLab CE/EE flaws allowing remote code execution, denial of service, and data confidentiality breaches, patched in 19.3.1.
ANSSI (CERT-FR) has published an advisory covering multiple vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE). The flaws collectively allow an attacker to achieve remote arbitrary code execution, remote denial of service, security policy bypass, and unauthorized access to confidential data. Affected versions include 19.2.x prior to 19.2.5, 19.3.x prior to 19.3.1, and all versions prior to 19.1.7.
GitLab addressed these issues in its August 26, 2026 security release (patch 19.3.1). Seven CVEs are referenced in the advisory (CVE-2025-10903, CVE-2026-15387, CVE-2026-18252, CVE-2026-3035, CVE-2026-4398, CVE-2026-7487, CVE-2026-77801), though the advisory does not provide per-CVE technical detail. Organizations running self-managed GitLab instances should prioritize upgrading to the fixed releases (19.1.7, 19.2.5, or 19.3.1 as applicable) given the breadth of impact spanning RCE, DoS, and data exposure.
No evidence of active exploitation is mentioned in the advisory; this is a routine vendor-patch notification relayed by the national CERT. Defenders should track GitLab's official release notes for technical specifics on each CVE and validate patch deployment across CI/CD and DevOps environments where GitLab is used, given its role as a critical software supply-chain component.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1086
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free