GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8
GitLab issued critical security patches for versions 19.3.2, 19.2.6, and 19.1.8 addressing six vulnerabilities, including remote file reads and remote code execution risks. Self-managed installations are urged to upgrade immediately.
GitLab released versions 19.3.2, 19.2.6, and 19.1.8 on September 10, 2026, for both Community and Enterprise Editions to address critical security and bug fixes. The company strongly recommends that all self-managed GitLab installations upgrade to one of these versions without delay. GitLab.com already runs the patched versions, and GitLab Dedicated customers require no action. Patch releases are issued twice monthly, with critical patches issued ad-hoc for high-severity vulnerabilities.
One vulnerability allowed unauthenticated users to read arbitrary files from GitLab servers due to improper path confinement and missing authentication enforcement in the repository commits API. This issue affected all versions from 18.7 prior to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2, with a maximum severity score of 10.0. The flaw was reported by s3ntago through GitLab’s HackerOne program.
Another issue permitted authenticated users with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials via a crafted GraphQL subscription argument, bypassing serialization. This vulnerability impacted all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2, with a severity score of 9.9. The issue was reported by kyyblin through the HackerOne program.
A third vulnerability enabled authenticated users to achieve remote code execution by importing a specially crafted Git project export, causing a buffer overflow in Advanced Search indexing. This flaw affected all versions from 12.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2, with a severity score of 8.5. The issue was reported by joaxcar through the HackerOne program.