GitLab Patch Release: 19.3.1, 19.2.5, 19.1.7
GitLab issued patch releases 19.3.1, 19.2.5, and 19.1.7 on August 26, 2026, addressing multiple security vulnerabilities in self-managed instances.
GitLab released versions 19.3.1, 19.2.5, and 19.1.7 on August 26, 2026, for both Community Edition and Enterprise Edition. These updates include critical bug fixes and security patches, and GitLab strongly advises all self-managed users to upgrade immediately. GitLab.com already runs the patched versions, while GitLab Dedicated customers require no action. Patch releases are issued twice monthly, with additional critical patches released as needed for high-severity vulnerabilities.
The updates address six security vulnerabilities, including a high-severity issue (CVSS 8.7) where an authenticated developer could execute arbitrary commands in a CI context via the Claude agent. Other vulnerabilities include denial-of-service risks and improper authorization checks affecting background job processing, SCIM user provisioning, and protected environments. Affected versions span multiple releases, with fixes applied to 19.3.1, 19.2.5, and 19.1.7.
GitLab also resolved a denial-of-service flaw in SCIM user provisioning triggered by crafted input, and an authorization bypass allowing project maintainers to access unauthorized protected environments. Additional issues included unauthorized compliance framework assignments and merge request approval rule resets by reporters. All vulnerabilities require authenticated access and carry CVSS scores ranging from 3.5 to 8.7.
The patch includes database migrations that may affect upgrade processes. Users should follow GitLab’s Update page for instructions and consult the Updating the Runner page for GitLab Runner updates. GitLab will disclose vulnerability details 90 days post-release on its issue tracker. Customers are urged to upgrade to the latest patch release to maintain security hygiene.