CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-10053

criticalpublic exploitCVSS 8.5covered by 3 sourcesfirst seen 2026-08-12
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2026-10053 is indexed in GitHub PoC. Expect opportunistic scanning and exploitation attempts — prioritize remediation even though it is not (yet) in the CISA KEV catalog.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.

CSIRTS triage

vendor: GitLabproduct: GitLabOtheraffected: 19.2.2, 19.1.4, 19.0.6
What
GitLab Community Edition and Enterprise Edition versions 19.2.2, 19.1.4, 19.0.6 address critical security and bug fixes.
Who is affected
Self-managed GitLab CE and EE installations on versions prior to 19.2.2, 19.1.4, 19.0.6.
Urgency
Critical severity; immediate upgrade required as stated by vendor for all self-managed installations.
Action
Upgrade self-managed GitLab installations to versions 19.2.2, 19.1.4, or 19.0.6 immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-10053

Get an email if CVE-2026-10053 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Exploit availability

Public exploit or proof-of-concept code for CVE-2026-10053 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.

Advisory coverage (3)

External references

NVD record for CVE-2026-10053

CVE.org record

Embed the live status

CVE-2026-10053 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-10053 status](https://www.csirts.com/badge/CVE-2026-10053)](https://www.csirts.com/cve/CVE-2026-10053)