OFICIAL GitLab Blog

GitLab Critical Patch Release: 19.4.1, 19.3.3, 19.2.7

What happened
Based on GitLab Blog · Sep 23, 2026

GitLab issued critical patch releases 19.4.1, 19.3.3, and 19.2.7 to address multiple security vulnerabilities across Community and Enterprise Editions, urging immediate upgrades for self-managed instances.

Key points
·
GitLab released critical patches 19.4.1, 19.3.3, and 19.2.7 on September 23, 2026 for CE and EE editions.
·
A high-severity vulnerability (CVSS 9.9) allowed arbitrary code execution via crafted CI/CD regex parsing in versions before 19.2.7, 19.3.3, and 19.4.1.
·
GitLab EE versions before 19.2.7, 19.3.3, and 19.4.1 had missing authorization checks exposing CI/CD variable values via Duo AI troubleshooting.

GitLab released versions 19.4.1, 19.3.3, and 19.2.7 on September 23, 2026, for both Community Edition and Enterprise Edition, containing critical bug and security fixes. The company strongly recommends that all self-managed GitLab installations upgrade to one of these versions immediately to address vulnerabilities. GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take any action.

Among the vulnerabilities addressed is a high-severity issue that could allow an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration. This vulnerability, with a CVSS score of 9.9, affects all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1.

Another remediated issue involves missing authorization checks in the Duo AI troubleshooting feature, which could allow an authenticated user to access sensitive CI/CD variable values from debug-mode job traces. This vulnerability, with a CVSS score of 7.7, affects GitLab Enterprise Edition versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1.

GitLab has also addressed multiple authorization-related vulnerabilities, including one that could allow an authenticated user with developer-role permissions to bypass AI tool governance controls, and another that could allow an unauthenticated user to read CI/CD job trace contents containing sensitive variable values. All vulnerabilities have been patched in the latest releases, and GitLab advises upgrading to the latest patch release for supported versions to maintain security hygiene.

Original source → Deals on Clipraptor.com →