GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5
GitLab released versions 19.2.1, 19.1.3, and 19.0.5 on July 29, 2026, addressing nine security vulnerabilities across Community and Enterprise Editions. Users are advised to upgrade immediately to mitigate risks including unauthorized data access, CI/CD manipulation, and denial-of-service attacks.
GitLab issued patch releases 19.2.1, 19.1.3, and 19.0.5 on July 29, 2026, for both Community Edition and Enterprise Edition. These updates address nine security vulnerabilities, including unauthorized information access and CI/CD configuration changes. The company strongly recommends that all self-managed installations upgrade immediately to prevent potential exploits.
Among the vulnerabilities remediated is an issue allowing authenticated users with Developer permissions to access unauthorized data due to insufficient access controls. Another flaw permitted modification of another user’s CI/CD configuration through improper validation of pipeline schedule inputs. Both vulnerabilities carry CVSS scores of 8.5 and 8.4, respectively, indicating high severity.
A denial-of-service vulnerability was also patched, enabling unauthenticated users to disrupt services by exploiting insufficient resource throttling during merge request discussions. Additionally, a race condition in approval rule processing allowed code merges into protected branches without required approvals. These issues affect multiple versions and carry CVSS scores ranging from 4.7 to 7.5.
GitLab.com is already running the patched versions, and GitLab Dedicated customers require no action. The company notes that patch releases are issued twice monthly, with critical vulnerabilities addressed as needed. Vulnerability details will be published 90 days post-release on GitLab’s issue tracker.