GitLab CE/EE security patch release (CVE-2023-2825, CVE-2026-87719)
Security Patch Release
Summary
Hide ▲
Show ▼
GitLab released fixes for CVE-2023-2825 and CVE-2026-87719 in GitLab Community Edition (CE) and Enterprise Edition (EE), requiring self-managed installations to upgrade immediately. The patch release addresses both a maximum-severity path traversal flaw and a critical insecure deserialization issue.
Related Happenings
GitLab self-managed installations immediate upgrade advisory
Advisory/Mitigation
H score37
First: 11.09.2026 14:15
Last: 11.09.2026 14:15
Sources 1
How related:
"These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately," the company warned on Thursday.
About this happening:
GitLab issued immediate upgrade guidance for self-managed GitLab installations after fixing two security issues in GitLab CE and GitLab EE. Operators were told...
GitLab self-managed installations immediate upgrade advisory
Advisory/MitigationHow related: "These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately," the company warned on Thursday.
About this happening: GitLab issued immediate upgrade guidance for self-managed GitLab installations after fixing two security issues in GitLab CE and GitLab EE. Operators were told...
HPE ArubaOS-CX security bulletin (CVE-2026-73749)
Security Patch Release
H score31
First: 03.09.2026 21:28
Last: 03.09.2026 21:28
Sources 1
About this happening:
HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code...
HPE ArubaOS-CX security bulletin (CVE-2026-73749)
Security Patch ReleaseAbout this happening: HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code...
GitLab CE/EE security update for CVE-2026-19478 and CVE-2026-19650
Security Patch Release
H score31
First: 18.08.2026 00:03
Last: 18.08.2026 00:03
Sources 1
About this happening:
GitLab released out-of-band security updates on August 17, 2026 for GitLab CE/EE to fix CVE-2026-19478, a critical GraphQL issue that could let an unauth...
GitLab CE/EE security update for CVE-2026-19478 and CVE-2026-19650
Security Patch ReleaseAbout this happening: GitLab released out-of-band security updates on August 17, 2026 for GitLab CE/EE to fix CVE-2026-19478, a critical GraphQL issue that could let an unauth...
Latest development: 21.08.2026 10:04
watchTowr observed in-the-wild exploitation of GitLab CVE-2026-19478 against its honeypot network and said it could reproduce the flaw within minutes of disclosure. GitLab said the issue could be exploited via a GraphQL directive, and defenders were told to hunt web logs for requests containing '@gl_introduced' and to restrict unauthenticated access to "/api/graphql" if patching is not immediately possible.
Gitea security patch release for CVE-2026-59774
Security Patch Release
H score65
First: 05.08.2026 14:04
Last: 05.08.2026 14:04
Sources 1
About this happening:
Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...
Gitea security patch release for CVE-2026-59774
Security Patch ReleaseAbout this happening: Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...
Gitea 1.27.1 security patch release for CVE-2026-60004
Security Patch Release
H score46
First: 29.07.2026 10:47
Last: 29.07.2026 10:47
Sources 1
About this happening:
Gitea's 1.27.1 security patch release closes CVE-2026-60004, a critical RCE affecting Gitea versions 1.17 through 1.27.0. The fix requires upgrading to 1.27.1,...
Gitea 1.27.1 security patch release for CVE-2026-60004
Security Patch ReleaseAbout this happening: Gitea's 1.27.1 security patch release closes CVE-2026-60004, a critical RCE affecting Gitea versions 1.17 through 1.27.0. The fix requires upgrading to 1.27.1,...
Timeline
-
11.09.2026 14:15 2 articles · 1h ago
GitLab releases fixes for CVE-2023-2825 and CVE-2026-87719
Mitigation Patch UpdateGitLab released fixes for CVE-2023-2825, a maximum-severity path traversal flaw in the repository commits API that could let unauthenticated attackers read arbitrary files under certain conditions, and CVE-2026-87719, a critical insecure deserialization issue in the GraphQL subscription serializer that can let authenticated GitLab EE users with Duo Chat access steal sensitive credentials and Advanced Search instance configurations. The company said GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 contain the fixes and that self-managed installations should upgrade immediately.
Show sources
- GitLab urges users to patch max severity path traversal flaw — www.bleepingcomputer.com — 11.09.2026 14:15
- GitLab urges users to patch max severity path traversal flaw — www.bleepingcomputer.com — 11.09.2026 14:15