[CIVN-2026-0457] Multiple Vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE)

By Published On: September 17, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE)


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


GitLab CE/EE 19.3.x versions prior to 19.3.2

GitLab CE/EE 19.2.x versions prior to 19.2.6

GitLab CE/EE from 10.1.0 to versions prior to 19.1.8

Overview


Multiple vulnerabilities have been reported in GitLab Community Edition (CE) and Enterprise Edition (EE) that could allow an attacker to execute arbitrary code, gain access to sensitive information, bypass security restrictions, or cause denial of service (DoS) conditions on the targeted system.


Target Audience:

Organizations and system administrators using self-managed GitLab CE or EE installations.


Risk Assessment:

High risk of remote code execution, unauthorized access, and sensitive information disclosure.


Impact Assessment:

Potential for complete system compromise.


Description


GitLab is a complete DevOps platform that provides source code management, CI/CD, and security features.


These vulnerabilities exist in GitLab CE/EE due to improper path confinement, insecure deserialization, buffer overflow, insufficient scope validation, improper sanitization, improper input validation, and other security weaknesses. A remote attacker could exploit these vulnerabilities by sending specially crafted requests to the affected GitLab components.


Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, gain access to sensitive information, bypass security restrictions, or cause denial of service (DoS) conditions on the targeted system.


Note:CVE-2026-85706 is being actively exploited in the wild. Users are strongly advised to apply the latest patches immediately.


Solution


Apply appropriate fixes as mentioned:

https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/



Vendor Information


 

https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/


References


 

https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/


CVE Name

CVE-2026-85706

CVE-2026-87719

CVE-2026-88765

CVE-2026-79708

CVE-2026-78252

CVE-2026-13210

CVE-2025-14871

CVE-2026-1168

CVE-2024-11222

CVE-2026-12910

CVE-2026-82837

CVE-2026-19619

CVE-2026-86341

CVE-2026-86340

CVE-2026-7514

CVE-2026-8030

CVE-2026-16794

CVE-2026-3855




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqr5LQACgkQ3jCgcSdc

ys/+gQ//UrVHgu5egQoNCB4Dw4CtbNibZ1Q9ZFErQVu/G0YqHYr5TKzVlaX+S+/w

cOrb4VxS19mgkVrd/U84JnGVJRCTOjyPNstJdirpDaRCKPkvYQMRINcQnRbKJQc8

ALPnLTgSZotVkwhlm7DB503wJ9BJpXkJb7fFXMBWCCBHst2Bvq0IHRw+ZIjjNH1E

6nchYQ85ixDGY2U+QjAhSS2F2oo5pjyYzYEXxx3yXDLLH7NEkWueYoGgTd9wxpdO

KIknJYgL4Ut1UPNrGka+L6m7Gt2RlVwuesa0EVo7lXwkupsTQmmTKs/DWLUW/XlX

es6GLj1RQy6SM5iy9kBGdHR/ZVIk6xVjTz/R0Etu/J0nZJiFc9eMDg/rZIuASuuQ

mMhMO4h2ULHEqKVZE46pg8W8xN+OujDqsMqfjcEcwTY4b/jztb/kjZirVhe8FTdW

0onfDa2IkRc+6ffqy+p269JXfDFJbiro2t6RhiEXY+/dr3NLKY4eGBd32/Ughlaj

NDERFissjSBX0xy1khGzJldEmfpBecG0CUUjUoZudO6X8r9JDZR8heZs6rrmkEQv

gSgNLvUxbhN77AadUcjgcsmD786ZuubE/XFABiOScy4EeO4Slh//LG5bMnYeZpND

Sm6iX77/Eox1gySayWIkJBzYlklbIo2MunwGYyEDPUk6zJFWqoU=

=7C52

—–END PGP SIGNATURE—–

Share this article