GitLab Product Security Update Advisory

GitLab Product Security Update Advisory

Overview


A security update has been released to address a vulnerability in GitLab products. This vulnerability affects GitLab CE/EE and is resolved by updating to the latest patched version.

Identified Vulnerabilities


  • CVE-2026-6267: A sensitive information exposure vulnerability in Workhorse (GitLab’s request-handling component) in GitLab CE/EE.
  • CVE-2026-12436: A CI/CD configuration tampering vulnerability in the Pipeline Schedule API (an API for managing CI/CD pipeline scheduling) of GitLab CE/EE.
  • CVE-2026-15975: A denial-of-service vulnerability in GitLab CE/EE’s Merge Request Discussions (a feature for merge request discussions).

Affected Versions


  • CVE-2026-6267: GitLab CE/EE 10.1.0 Or later but earlier than 19.0.5, 19.1 Or later but earlier than 19.1.3, And 19.2 Or later but earlier than 19.2.1.
  • CVE-2026-12436: GitLab CE/EE 18.0 Or later but earlier than 19.0.5, 19.1 Or later but earlier than 19.1.3, And 19.2 Or later but earlier than 19.2.1.
  • CVE-2026-15975: GitLab CE/EE 11.8 Or later but earlier than 19.0.5, 19.1 Or later but earlier than 19.1.3, 19.2 Or later but earlier than 19.2.1.

Action


GitLab has released patch versions 19.0.5 Or later, 19.1.3 Or later, and 19.2.1 Or later. You must update to these versions following the instructions on the reference site.