GitLab Critical Patch Release: 19.4.1, 19.3.3, 19.2.7
GitLab issued critical patch releases 19.4.1, 19.3.3, and 19.2.7 to address multiple security vulnerabilities across Community and Enterprise Editions, urging immediate upgrades for self-managed instances.
GitLab released versions 19.4.1, 19.3.3, and 19.2.7 on September 23, 2026, for both Community Edition and Enterprise Edition, containing critical bug and security fixes. The company strongly recommends that all self-managed GitLab installations upgrade to one of these versions immediately to address vulnerabilities. GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take any action.
Among the vulnerabilities addressed is a high-severity issue that could allow an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration. This vulnerability, with a CVSS score of 9.9, affects all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1.
Another remediated issue involves missing authorization checks in the Duo AI troubleshooting feature, which could allow an authenticated user to access sensitive CI/CD variable values from debug-mode job traces. This vulnerability, with a CVSS score of 7.7, affects GitLab Enterprise Edition versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1.
GitLab has also addressed multiple authorization-related vulnerabilities, including one that could allow an authenticated user with developer-role permissions to bypass AI tool governance controls, and another that could allow an unauthenticated user to read CI/CD job trace contents containing sensitive variable values. All vulnerabilities have been patched in the latest releases, and GitLab advises upgrading to the latest patch release for supported versions to maintain security hygiene.