
[CIVN-2026-0457] Multiple Vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE)
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE)
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
GitLab CE/EE 19.3.x versions prior to 19.3.2
GitLab CE/EE 19.2.x versions prior to 19.2.6
GitLab CE/EE from 10.1.0 to versions prior to 19.1.8
Overview
Multiple vulnerabilities have been reported in GitLab Community Edition (CE) and Enterprise Edition (EE) that could allow an attacker to execute arbitrary code, gain access to sensitive information, bypass security restrictions, or cause denial of service (DoS) conditions on the targeted system.
Target Audience:
Organizations and system administrators using self-managed GitLab CE or EE installations.
Risk Assessment:
High risk of remote code execution, unauthorized access, and sensitive information disclosure.
Impact Assessment:
Potential for complete system compromise.
Description
GitLab is a complete DevOps platform that provides source code management, CI/CD, and security features.
These vulnerabilities exist in GitLab CE/EE due to improper path confinement, insecure deserialization, buffer overflow, insufficient scope validation, improper sanitization, improper input validation, and other security weaknesses. A remote attacker could exploit these vulnerabilities by sending specially crafted requests to the affected GitLab components.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, gain access to sensitive information, bypass security restrictions, or cause denial of service (DoS) conditions on the targeted system.
Note:CVE-2026-85706 is being actively exploited in the wild. Users are strongly advised to apply the latest patches immediately.
Solution
Apply appropriate fixes as mentioned:
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
Vendor Information
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
References
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
CVE Name
CVE-2026-85706
CVE-2026-87719
CVE-2026-88765
CVE-2026-79708
CVE-2026-78252
CVE-2026-13210
CVE-2025-14871
CVE-2026-1168
CVE-2024-11222
CVE-2026-12910
CVE-2026-82837
CVE-2026-19619
CVE-2026-86341
CVE-2026-86340
CVE-2026-7514
CVE-2026-8030
CVE-2026-16794
CVE-2026-3855
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqr5LQACgkQ3jCgcSdc
ys/+gQ//UrVHgu5egQoNCB4Dw4CtbNibZ1Q9ZFErQVu/G0YqHYr5TKzVlaX+S+/w
cOrb4VxS19mgkVrd/U84JnGVJRCTOjyPNstJdirpDaRCKPkvYQMRINcQnRbKJQc8
ALPnLTgSZotVkwhlm7DB503wJ9BJpXkJb7fFXMBWCCBHst2Bvq0IHRw+ZIjjNH1E
6nchYQ85ixDGY2U+QjAhSS2F2oo5pjyYzYEXxx3yXDLLH7NEkWueYoGgTd9wxpdO
KIknJYgL4Ut1UPNrGka+L6m7Gt2RlVwuesa0EVo7lXwkupsTQmmTKs/DWLUW/XlX
es6GLj1RQy6SM5iy9kBGdHR/ZVIk6xVjTz/R0Etu/J0nZJiFc9eMDg/rZIuASuuQ
mMhMO4h2ULHEqKVZE46pg8W8xN+OujDqsMqfjcEcwTY4b/jztb/kjZirVhe8FTdW
0onfDa2IkRc+6ffqy+p269JXfDFJbiro2t6RhiEXY+/dr3NLKY4eGBd32/Ughlaj
NDERFissjSBX0xy1khGzJldEmfpBecG0CUUjUoZudO6X8r9JDZR8heZs6rrmkEQv
gSgNLvUxbhN77AadUcjgcsmD786ZuubE/XFABiOScy4EeO4Slh//LG5bMnYeZpND
Sm6iX77/Eox1gySayWIkJBzYlklbIo2MunwGYyEDPUk6zJFWqoU=
=7C52
—–END PGP SIGNATURE—–


