GitLab Patch Release: 19.2.2, 19.1.4, 19.0.6
GitLab issued patch releases 19.2.2, 19.1.4, and 19.0.6 on August 12, 2026, addressing multiple security vulnerabilities across Community and Enterprise Editions. Self-managed instances are advised to upgrade immediately, while GitLab.com and Dedicated customers require no action.
GitLab released versions 19.2.2, 19.1.4, and 19.0.6 on August 12, 2026, to address critical security and bug fixes for both Community Edition (CE) and Enterprise Edition (EE). The company strongly recommends that all self-managed installations upgrade to one of these versions without delay. GitLab.com has already implemented the patches, and GitLab Dedicated customers are unaffected. Patch releases are issued twice monthly, with additional critical updates released as needed.
The updates resolve nine security vulnerabilities, including a high-severity cross-site scripting flaw in an analytics dashboard component (CVSS 8.7) and an authorization bypass allowing unauthorized CI/CD pipeline execution on protected branches (CVSS 8.5). Other issues include improper identity attribution in AI usage, unauthorized project setting modifications, and denial-of-service risks due to insufficient input validation.
Additional vulnerabilities addressed include unauthorized access to merge request data, bypassing IP-based restrictions, and exposure of restricted configuration settings. Most issues affect multiple versions, spanning from 12.0 to 19.2, with severity ratings ranging from 4.3 to 8.7. GitLab notes that vulnerabilities are disclosed publicly on its issue tracker 90 days after patching.
GitLab emphasizes maintaining strong security practices by upgrading to the latest patch release for supported versions. The company advises reviewing its security best practices documentation and upgrading installations running affected versions as soon as possible to mitigate potential risks.