news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans GitLab (11 septembre 2026)

High
Summary

Multiple vulnerabilities have been discovered in GitLab, including remote code execution, denial of service, and data confidentiality breaches. These vulnerabilities affect GitLab Community and Enterprise Editions versions prior to 19.1.8, 19.2.x (prior to 19.2.6), 19.3.x (prior to 19.3.2). Users are advised to consult the provided security patch release documentation for remediation.

A security advisory from CERT-FR details multiple vulnerabilities within GitLab. These vulnerabilities allow for remote code execution, denial of service attacks, and compromise of data confidentiality. Specifically, versions of GitLab Community Edition and Enterprise Edition prior to 19.1.8, 19.2.x (prior to 19.2.6), and 19.3.x (prior to 19.3.2) are affected. The vulnerabilities include remote code execution, denial of service, and data confidentiality breaches. The CERT-FR documentation provides links to the security patch release for GitLab (https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/). The advisory lists a comprehensive set of CVE identifiers, including CVE-2024-11222, CVE-2025-14871, CVE-2026-1168, CVE-2026-12910, CVE-2026-13210, CVE-2026-16794, CVE-2026-19619, CVE-2026-3855, CVE-2026-7514, CVE-2026-78252, CVE-2026-79708, CVE-2026-8030, CVE-2026-82837, CVE-2026-85706, CVE-2026-86340, CVE-2026-86341, CVE-2026-87719, and CVE-2026-88765.

Read the full article at CERT-FR