OSG-SEC-2026-09-11 CRITICAL-Multiple Vulnerabilities in Self-Managed GitLab CE/EE
Dear OSG Security Contacts,
Multiple vulnerabilities have been identified in self-managed GitLab Community Edition (CE) and Enterprise Edition (EE), including two Critical vulnerabilities [1]. GitLab has released a critical security update and recommends that affected self-managed installations be upgraded.
WHAT ARE THE VULNERABILITIES:
The most severe vulnerabilities addressed by this update include: CVE-2026-85706 – Path Traversal / Arbitrary File Read (CVSS 10.0 – Critical). A path traversal vulnerability exists in GitLab's repository commits API. Under certain conditions, improper path confinement and missing authentication enforcement may allow an unauthenticated remote attacker to read arbitrary files from the GitLab server. Successful exploitation could expose sensitive information accessible to the GitLab service, potentially including configuration data, credentials, tokens, or other secrets.
CVE-2026-87719 – Insecure Deserialization (CVSS 9.9 – Critical) An insecure deserialization vulnerability exists in GitLab EE's GraphQL subscription serializer. Under certain conditions, an authenticated user with GitLab Duo Chat access could use a specially crafted GraphQL subscription argument to obtain Advanced Search instance configurations and sensitive credentials.
CVE-2026-88765 – Buffer Overflow / Remote Code Execution (CVSS 8.5 – High) A buffer overflow vulnerability in GitLab EE may allow an authenticated user to achieve remote code execution (RCE) by importing a specially crafted Git project export that triggers a buffer overflow during Advanced Search indexing.
The GitLab security release also addresses several additional High, Medium, and Low severity vulnerabilities [1]. At this time, we are not aware of publicly available proof-of-concept (PoC) exploits or confirmed exploitation in the wild for the above vulnerabilities. However, given the unauthenticated attack vector and severity of CVE-2026-85706, affected systems should be updated as soon as possible.
IMPACTED VERSIONS:
For the most critical vulnerability, CVE-2026-85706, the following GitLab CE/EE versions are affected:
GitLab 18.7 through versions earlier than 19.1.8;
GitLab 19.2 through versions earlier than 19.2.6; and
GitLab 19.3 through versions earlier than 19.3.2.
Affected version ranges vary for the other vulnerabilities. Sites should refer to the GitLab security advisory [1] for complete version-specific information.
MITIGATION
GitLab recommends upgrading affected self-managed GitLab installations to a patched version.
WHAT YOU SHOULD DO:
Identify any self-managed GitLab CE or EE instances and determine their installed versions. Upgrade affected self-managed installations to: GitLab 19.1.8 or later; GitLab 19.2.6 or later; or GitLab 19.3.2 or later. Sites running older GitLab release branches should upgrade to an appropriate currently supported and patched release. Because CVE-2026-85706 can be exploited remotely without authentication, Internet-accessible affected GitLab instances should be prioritized for immediate remediation.
REFERENCES
[1] https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/.
[2] https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/.