OFICIAL GitLab Blog

GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8

What happened
Based on GitLab Blog · Sep 11, 2026

GitLab issued critical security patches for versions 19.3.2, 19.2.6, and 19.1.8 addressing six vulnerabilities, including remote file reads and remote code execution risks. Self-managed installations are urged to upgrade immediately.

Key points
·
GitLab released versions 19.3.2, 19.2.6, and 19.1.8 on September 10, 2026, to address critical security flaws in self-managed installations.
·
Unauthenticated users could read arbitrary files due to improper path confinement in the repository commits API, with a severity score of 10.0.
·
Authenticated users could achieve remote code execution by importing a crafted Git project export, affecting versions from 12.3 to 19.3.

GitLab released versions 19.3.2, 19.2.6, and 19.1.8 on September 10, 2026, for both Community and Enterprise Editions to address critical security and bug fixes. The company strongly recommends that all self-managed GitLab installations upgrade to one of these versions without delay. GitLab.com already runs the patched versions, and GitLab Dedicated customers require no action. Patch releases are issued twice monthly, with critical patches issued ad-hoc for high-severity vulnerabilities.

One vulnerability allowed unauthenticated users to read arbitrary files from GitLab servers due to improper path confinement and missing authentication enforcement in the repository commits API. This issue affected all versions from 18.7 prior to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2, with a maximum severity score of 10.0. The flaw was reported by s3ntago through GitLab’s HackerOne program.

Another issue permitted authenticated users with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials via a crafted GraphQL subscription argument, bypassing serialization. This vulnerability impacted all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2, with a severity score of 9.9. The issue was reported by kyyblin through the HackerOne program.

A third vulnerability enabled authenticated users to achieve remote code execution by importing a specially crafted Git project export, causing a buffer overflow in Advanced Search indexing. This flaw affected all versions from 12.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2, with a severity score of 8.5. The issue was reported by joaxcar through the HackerOne program.

Original source → Deals on Clipraptor.com →