GitLab Product Security Update Advisory
Overview
A security update has been released to address vulnerabilities in GitLab products. GitLab CE/EE users should update to the latest version with security patches.
Affected Products and Versions
- GitLab CE/EE 18.2 Or later, but earlier than 18.11.11.
- GitLab CE/EE 19.0 Or later, but earlier than 19.0.8.
- GitLab CE/EE 19.1 Or later, but earlier than 19.1.6.
- GitLab CE/EE 19.2 Or later, but earlier than 19.2.4.
Resolved Vulnerabilities
- CVE-2026-19478: A code injection vulnerability in the GraphQL directive of GitLab CE/EE. Code injection is a vulnerability that allows a threat actor to inject and execute unintended code.
- CVE-2026-19650: A cross-site request forgery (CSRF) vulnerability occurring during the processing of GraphQL multiplex queries in GitLab CE/EE. CSRF is a vulnerability that allows requests to be sent contrary to the user’s intentions.
Mitigation Steps
- Update GitLab CE/EE to the latest version with Vulnerability Patches.
- The versions with Vulnerability Patches are 18.11.11, 19.0.8, 19.1.6, And 19.2.4.
Notes
- GitLab Critical Patch Releases: 19.2.4, 19.1.6, 19.0.8, 18.11.11.