GitLab Product Security Update Advisory

GitLab Product Security Update Advisory

Overview


A security update has been released to address vulnerabilities in GitLab products. GitLab CE/EE users should update to the latest version with security patches.

Affected Products and Versions


  • GitLab CE/EE 18.2 Or later, but earlier than 18.11.11.
  • GitLab CE/EE 19.0 Or later, but earlier than 19.0.8.
  • GitLab CE/EE 19.1 Or later, but earlier than 19.1.6.
  • GitLab CE/EE 19.2 Or later, but earlier than 19.2.4.

Resolved Vulnerabilities


  • CVE-2026-19478: A code injection vulnerability in the GraphQL directive of GitLab CE/EE. Code injection is a vulnerability that allows a threat actor to inject and execute unintended code.
  • CVE-2026-19650: A cross-site request forgery (CSRF) vulnerability occurring during the processing of GraphQL multiplex queries in GitLab CE/EE. CSRF is a vulnerability that allows requests to be sent contrary to the user’s intentions.

Mitigation Steps


  • Update GitLab CE/EE to the latest version with Vulnerability Patches.
  • The versions with Vulnerability Patches are 18.11.11, 19.0.8, 19.1.6, And 19.2.4.

Notes


  • GitLab Critical Patch Releases: 19.2.4, 19.1.6, 19.0.8, 18.11.11.