Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure, remote code execution, cross-site scripting, denial of service condition and security restriction bypass on the targeted system. Note: CVE-2026-... Impact Information Disclosure Security Restriction Bypass Remote Code Execution Cross-Site Scripting Denial of Service System / Technologies affected GitLab Community Edition (CE) versions prior to 19.3.2, 19.2.6, 19.1.8 GitLab Enterprise Edition (EE) versions prior to 19.3.2, 19.2.6, 19.1.8 Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/?nav=19.3.2
Multiple vulnerabilities in GitLab, including remote code execution, information disclosure, cross-site scripting, denial of service, and security restriction bypass, can be exploited by a remote attacker. Affected versions are GitLab Community and Enterprise Editions prior to 19.3.2, 19.2.6, and 19.1.8. The vendor has released fixes; administrators should apply the patches detailed in the official release notes for version 19.3.2 and other specified patch releases.