GITLAB released a patch on August 12, 2026, addressing 13 security flaws in versions 19.2.2, 19.1.4, and 19.0.6. The most critical issues are high-severity cross-site scripting bugs, with CVSS scores of 8.7. There have been no confirmed exploits for these vulnerabilities. Users are urged to upgrade immediately to mitigate risks, as many flaws could potentially be abused by users with developer access. The vulnerabilities include issues in CI/CD authorization and pipeline configurations. Complete details are available in the official patch release notes.
GitLab issues patch for 13 flaws, including high risk XSS
CyberSIXT Evidence Panel
Primary Source
docs.gitlab.com
Article by CyberSIXT