[CIVN-2026-0389] Multiple Vulnerabilities in GitLab

By Published On: August 5, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in GitLab


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


GitLab versions prior to 19.0.5, 19.1.3, and 19.2.1 for GitLab Community Edition (CE) and Enterprise Edition (EE)

Overview


Multiple vulnerabilities have been reported in GitLab CE/EE which could allow a remote attacker to gain unauthorized access to sensitive information, modify CI/CD or project configurations, bypass security restrictions, execute cross-site scripting (XSS) attacks or cause a denial-of-service (DoS) condition on the targeted system.


Target Audience:

Organizations and individuals using GitLab CE/EE instances.


Risk Assessment:

High risk of unauthorized access to sensitive information, unauthorized modification of CI/CD and project configurations, bypassing of security controls, cross-site scripting and disruption of services.


Impact Assessment:

Potential for unauthorized disclosure of sensitive information, modification of CI/CD and protected-branch configurations, bypassing of merge-request approval and governance controls, cross-site scripting attacks and denial-of-service conditions.


Description


GitLab is a web-based DevOps platform that provides tools for software developments, including source code management, continuous integration and continuous deployment. It is available in both open-source Community Edition (CE) and Enterprise Edition (EE) versions.


Multiple vulnerabilities exist in GitLab Community Edition (CE) and Enterprise Edition (EE) due to insufficient access controls, improper authorization, improper validation of user-supplied attributes, mass assignment, race conditions, improper sanitization of user-controlled input, insufficient resource throttling, improper handling of sensitive information, prompt injection in AI-assisted functionality and incorrect security-token generation.


Successful exploitation of these vulnerabilities could allow a remote attacker to gain unauthorized access to sensitive information, modify CI/CD or project configurations, bypass security restrictions, execute cross-site scripting (XSS) attacks or cause a denial-of-service (DoS) condition on the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

http://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/?nav=19.2.1/



Vendor Information


GitLab

http://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/?nav=19.2.1/


References


 

http://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/?nav=19.2.1/


CVE Name

CVE-2026-6267

CVE-2026-12436

CVE-2026-15975

CVE-2026-13113

CVE-2026-16553

CVE-2026-6336

CVE-2026-14341

CVE-2026-3093

CVE-2026-15077

CVE-2026-15831

CVE-2026-14351

CVE-2026-4672

CVE-2026-14562




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpzRNoACgkQ3jCgcSdc

ys9kJQ//YE9DOJcNwMZf45msLqnqojWWnelDvQ1xhW0GDGjLh+91DzsYz1YlS54+

8NxPuYJV23cZXhOcwUgPOuX6Wkm+iJFS9KDMk5dbGisI6kD0FzBHdHZe8js7Snf3

G8kVRVkWrEW5JsPbl/pqlDLGGVwDCkERes3aApdCKLsC/2EJZeiyy2U/Bo2frcwz

Rz3/GMWQqwFkRnyaxQiqJPd+a5qT5/jp2Gi3j+bDCgBC4HXtfWa53oeAQkqxiwJu

nH1bIQH55wO5SfX+eTmtAwE2lxcsDONykujb+RiOHtEnaT29BL7TfyuseG3Iq7aS

aMVKAV1fUGxGQxE+4hQCOpPB1ZgtDdATvVu1IjA8kobZOedVUY/zCXT2uO/xv36x

APGzO164gzXY9HSe68wFbd3bNH+2WLw3weKX/WDqGZZIfWHCAtBDb0Kos1W6D32T

fPeeUs2GQiA4hgItj9KwfMmOjnLmOAto3pcHujFVHV3PAwrJS5q0dQSyBElsOdyY

jIc2W05HZQJmmAp2xYcVVWy9xr4dyXrDJaW9lcuMNPzb19msUDj9cPOGcfJFhi0n

Y2rqj5+MLgKUp8RDjEI6wkOx3bZUo+NRbDZf2G7PGhV0vaRk/r1/4sxXzqztjdv/

MfID2uWDDpjdaHYTCEOtPyl985M5DECTLMSHuPTyilM5cYZxf+k=

=eSRP

—–END PGP SIGNATURE—–

Share this article