GitLab has released new critical security updates for its Community Edition (CE) and Enterprise Edition (EE) , addressing a total of eight vulnerabilities that could, under certain circumstances, allow attackers to gain access to sensitive data or execute malicious code . The company urges all self-managed deployment administrators to install the new releases immediately to mitigate the risk of exploiting the vulnerabilities.

The fixes are included in versions 19.1.2, 19.0.4 , and 18.11.7, which were released on July 8, 2026 , and address vulnerabilities of high, medium, and low severity. Although the GitLab.com has already been updated with the necessary patches, organizations that host GitLab on their own infrastructure are still exposed until they complete the upgrade process.
GitLab: The most serious vulnerabilities fixed
Among the most significant security issues, the vulnerability CVE-2026-6896, which is classified as high severity and concerns Cross-Site Scripting (XSS) in the Enterprise Edition.
See also: RoguePlanet: Microsoft patches critical Defender vulnerability
According to GitLab, a user with developer-level privileges could exploit the vulnerability to inject malicious JavaScript into other users' browsers. The vulnerability is due to insufficient sanitization of user-supplied input that appears in the vulnerability evidence table.
With a CVSS score of 8.7, this vulnerability is considered particularly dangerous, as it can lead to session hijacking, information leakage , or even gaining unauthorized access to user accounts.
Equally important is CVE-2026-13320 , an HTML Injection vulnerability that affects both CE and EE versions. In certain scenarios, an attacker could inject malicious content into the platform's Wiki pages, leading to the execution of arbitrary code in the browser of users who visit the relevant content.
Problems of access and information leakage
The fixes aren't limited to XSS attacks. GitLab also addressed several moderate-severity vulnerabilities related to access control mechanisms.
CVE-2026-11827 is a vulnerability in the Enterprise Edition repository mirroring feature . Under certain circumstances, users with maintainer-level privileges could gain access to stored credentials due to inadequate protection of the information.

At the same time, CVE-2026-8472 affects the management of Work Items, potentially allowing the leakage of metadata from private repositories to unauthorized users.
Another issue, CVE-2026-7492, could allow even unlogged visitors to infer the existence of private projects from references to commit-related discussions. While the project data is not directly revealed, such information can be used in the reconnaissance phase before a more complex cyberattack.
See also: Wireshark 4.6.7 fixes 12 security issues across multiple protocols
Additional fixes and improvements
The new release also includes fixes for several lower severity vulnerabilities, relating to incorrect authorization checks in group settings, compliance functions, and Git reference management.
A typical example is CVE-2025-12506, which could cause a discrepancy between the content displayed in a repository and what was ultimately available for download.
At the same time, GitLab took the opportunity to incorporate performance improvements, bug fixes, and upgrades to key platform dependencies, such as the move to Go 1.25.11. In addition, memory leak issues were addressed, while the operation of OAuth mechanisms.
What should administrators do?
The company emphasizes that organizations using self-managed deployments should not delay installing the new updates. Upgrades involve database migrations, which can cause temporary downtime in single-server deployments. In contrast, multi-node environments can perform the upgrade with zero-downtime, significantly reducing downtime.
GitLab points out that as long as known vulnerabilities remain unpatched, the chances of them becoming the target of automated attacks by cybercriminals looking for unpatched systems increase.
See also: GhostApproval: Symlink vulnerabilities in AI coding agents

The importance of timely updates
Cybersecurity incidents in recent years have shown that attacks often start from known vulnerabilities for which patches are already available but have not been installed in a timely manner. Platforms like GitLab are a key software development tool for thousands of businesses and organizations, making them a particularly attractive target.
Implementing new releases immediately not only eliminates the risk of exploiting these vulnerabilities, but also strengthens the overall security of your software development infrastructure. For this reason, GitLab recommends that all administrators schedule the upgrade as soon as possible to ensure the protection of their repositories, data, and user accounts.
