Find notable cyber news and cases, enriched with sources, timelines, and signals.

GitLab CE/EE security patch release (CVE-2023-2825, CVE-2026-87719)

Security Patch Release
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

GitLab released fixes for CVE-2023-2825 and CVE-2026-87719 in GitLab Community Edition (CE) and Enterprise Edition (EE), requiring self-managed installations to upgrade immediately. The patch release addresses both a maximum-severity path traversal flaw and a critical insecure deserialization issue.

Related Happenings

GitLab self-managed installations immediate upgrade advisory

Advisory/Mitigation
H score37 First: 11.09.2026 14:15 Last: 11.09.2026 14:15 Sources 1

How related: "These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately," the company warned on Thursday.

About this happening: GitLab issued immediate upgrade guidance for self-managed GitLab installations after fixing two security issues in GitLab CE and GitLab EE. Operators were told...

HPE ArubaOS-CX security bulletin (CVE-2026-73749)

Security Patch Release
H score31 First: 03.09.2026 21:28 Last: 03.09.2026 21:28 Sources 1

About this happening: HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code...

GitLab CE/EE security update for CVE-2026-19478 and CVE-2026-19650

Security Patch Release
H score31 First: 18.08.2026 00:03 Last: 18.08.2026 00:03 Sources 1

About this happening: GitLab released out-of-band security updates on August 17, 2026 for GitLab CE/EE to fix CVE-2026-19478, a critical GraphQL issue that could let an unauth...

Latest development: 21.08.2026 10:04

watchTowr observed in-the-wild exploitation of GitLab CVE-2026-19478 against its honeypot network and said it could reproduce the flaw within minutes of disclosure. GitLab said the issue could be exploited via a GraphQL directive, and defenders were told to hunt web logs for requests containing '@gl_introduced' and to restrict unauthenticated access to "/api/graphql" if patching is not immediately possible.

Gitea security patch release for CVE-2026-59774

Security Patch Release
H score65 First: 05.08.2026 14:04 Last: 05.08.2026 14:04 Sources 1

About this happening: Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...

Gitea 1.27.1 security patch release for CVE-2026-60004

Security Patch Release
H score46 First: 29.07.2026 10:47 Last: 29.07.2026 10:47 Sources 1

About this happening: Gitea's 1.27.1 security patch release closes CVE-2026-60004, a critical RCE affecting Gitea versions 1.17 through 1.27.0. The fix requires upgrading to 1.27.1,...

Timeline

  1. 11.09.2026 14:15 2 articles · 1h ago

    GitLab releases fixes for CVE-2023-2825 and CVE-2026-87719

    Mitigation Patch Update

    GitLab released fixes for CVE-2023-2825, a maximum-severity path traversal flaw in the repository commits API that could let unauthenticated attackers read arbitrary files under certain conditions, and CVE-2026-87719, a critical insecure deserialization issue in the GraphQL subscription serializer that can let authenticated GitLab EE users with Duo Chat access steal sensitive credentials and Advanced Search instance configurations. The company said GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 contain the fixes and that self-managed installations should upgrade immediately.

    Show sources