Security · October 2, 2026

GitLab issues security updates for legacy branches addressing critical vulnerabilities

a person holding a phone
Onur Binay / Unsplash

GitLab has implemented backports for legacy branches following the discovery of serious vulnerabilities in its development tools. On September 23, 2026, GitLab released versions "19.0.9" and "18.11.12" to address vulnerabilities identified as "CVE-2026-85706" and "CVE-2026-87719."

Previously, on September 10, the company released versions "19.3.2," "19.2.6," and "19.1.8," addressing vulnerabilities rated as "Critical" on a four-tier scale. Despite these updates typically not covering legacy branches under regular maintenance policies, GitLab provided updates for those versions as well.

"CVE-2026-85706" is a vulnerability resulting from issues with path restrictions and authentication processes within the repository's "commits API." Under certain conditions, it allows unauthorized reading of arbitrary files within a GitLab server. The Common Vulnerability Scoring System (CVSSv3.1) assigned a base score of "10.0" to this vulnerability, which has already been confirmed to be exploited. GitLab has also shared information to detect attempts of exploitation.

In contrast, "CVE-2026-87719" affects only the Enterprise Edition (EE). This vulnerability poses a risk of exposure for sensitive authentication information and settings related to the "Advanced Search" feature, with a CVSS base score of "9.9."