GitLab self-managed installations immediate upgrade advisory
Advisory/Mitigation
Summary
Hide ▲
Show ▼
GitLab issued immediate upgrade guidance for self-managed GitLab installations after fixing two security issues in GitLab CE and GitLab EE. Operators were told to move to 19.3.2, 19.2.6, or 19.1 without delay. The guidance reduces exposure to CVE-2023-2825 and CVE-2026-87719, which can enable arbitrary file reads or sensitive credential theft under certain conditions.
Related Happenings
GitLab CE/EE security patch release (CVE-2023-2825, CVE-2026-87719)
Security Patch Release
H score37
First: 11.09.2026 14:15
Last: 11.09.2026 14:15
Sources 1
How related:
GitLab fixed the two security issues in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
About this happening:
GitLab released fixes for CVE-2023-2825 and CVE-2026-87719 in GitLab Community Edition (CE) and Enterprise Edition (EE), requiring self-managed installations...
GitLab CE/EE security patch release (CVE-2023-2825, CVE-2026-87719)
Security Patch ReleaseHow related: GitLab fixed the two security issues in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
About this happening: GitLab released fixes for CVE-2023-2825 and CVE-2026-87719 in GitLab Community Edition (CE) and Enterprise Edition (EE), requiring self-managed installations...
GitLab repository commits API path traversal vulnerability (CVE-2023-2825)
Vulnerability
H score33
First: 11.09.2026 14:15
Last: 11.09.2026 14:15
Sources 1
How related:
According to GitLab, unauthenticated attackers can exploit CVE-2023-2825 to read arbitrary files from vulnerable servers "under certain conditions."
About this happening:
GitLab has a maximum-severity path traversal vulnerability, CVE-2023-2825, that can let unauthenticated attackers read arbitrary files from vulnerable servers...
GitLab repository commits API path traversal vulnerability (CVE-2023-2825)
VulnerabilityHow related: According to GitLab, unauthenticated attackers can exploit CVE-2023-2825 to read arbitrary files from vulnerable servers "under certain conditions."
About this happening: GitLab has a maximum-severity path traversal vulnerability, CVE-2023-2825, that can let unauthenticated attackers read arbitrary files from vulnerable servers...
GitLab CE/EE security update for CVE-2026-19478 and CVE-2026-19650
Security Patch Release
H score31
First: 18.08.2026 00:03
Last: 18.08.2026 00:03
Sources 1
About this happening:
GitLab released out-of-band security updates on August 17, 2026 for GitLab CE/EE to fix CVE-2026-19478, a critical GraphQL issue that could let an unauth...
GitLab CE/EE security update for CVE-2026-19478 and CVE-2026-19650
Security Patch ReleaseAbout this happening: GitLab released out-of-band security updates on August 17, 2026 for GitLab CE/EE to fix CVE-2026-19478, a critical GraphQL issue that could let an unauth...
Latest development: 21.08.2026 10:04
watchTowr observed in-the-wild exploitation of GitLab CVE-2026-19478 against its honeypot network and said it could reproduce the flaw within minutes of disclosure. GitLab said the issue could be exploited via a GraphQL directive, and defenders were told to hunt web logs for requests containing '@gl_introduced' and to restrict unauthenticated access to "/api/graphql" if patching is not immediately possible.
GitLab notebook diff authenticated RCE flaw
Vulnerability
H score37
First: 25.07.2026 11:34
Last: 25.07.2026 11:34
Sources 1
About this happening:
A public PoC exploit now shows an authenticated RCE path in GitLab that can run commands as git on vulnerable self-managed servers. The flaw affects GitLab CE/EE...
GitLab notebook diff authenticated RCE flaw
VulnerabilityAbout this happening: A public PoC exploit now shows an authenticated RCE path in GitLab that can run commands as git on vulnerable self-managed servers. The flaw affects GitLab CE/EE...
GitLab CE/EE SSRF flaw (CVE-2021-39935)
Vulnerability
H score1
First: 04.02.2026 17:42
Last: 04.02.2026 17:42
Sources 1
About this happening:
GitLab CE/EE CVE-2021-39935 is an actively exploited SSRF flaw that lets unauthenticated external users make server-side requests through the CI Lint API. The...
GitLab CE/EE SSRF flaw (CVE-2021-39935)
VulnerabilityAbout this happening: GitLab CE/EE CVE-2021-39935 is an actively exploited SSRF flaw that lets unauthenticated external users make server-side requests through the CI Lint API. The...
Timeline
-
11.09.2026 14:15 2 articles · 1h ago
GitLab urges immediate upgrade of self-managed installations after patching two security issues
Mitigation Patch UpdateGitLab released fixes for self-managed GitLab installations and urged operators to upgrade immediately to versions 19.3.2, 19.2.6, or 19.1. The patched issues include CVE-2023-2825, a maximum-severity path traversal flaw that can let unauthenticated attackers read arbitrary files under certain conditions, and CVE-2026-87719, a critical insecure deserialization weakness in the GraphQL subscription serializer that affects GitLab EE and can let authenticated users with Duo Chat access steal sensitive credentials and Advanced Search instance configurations. GitLab.com was already running the patched version, and GitLab Dedicated customers did not need to take action.
Show sources
- GitLab urges users to patch max severity path traversal flaw — www.bleepingcomputer.com — 11.09.2026 14:15
- GitLab urges users to patch max severity path traversal flaw — www.bleepingcomputer.com — 11.09.2026 14:15