CVE-2026-10053
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2026-10053 is indexed in GitHub PoC. Expect opportunistic scanning and exploitation attempts — prioritize remediation even though it is not (yet) in the CISA KEV catalog.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.
CSIRTS triage
- What
- GitLab Community Edition and Enterprise Edition versions 19.2.2, 19.1.4, 19.0.6 address critical security and bug fixes.
- Who is affected
- Self-managed GitLab CE and EE installations on versions prior to 19.2.2, 19.1.4, 19.0.6.
- Urgency
- Critical severity; immediate upgrade required as stated by vendor for all self-managed installations.
- Action
- Upgrade self-managed GitLab installations to versions 19.2.2, 19.1.4, or 19.0.6 immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-10053
Get an email if CVE-2026-10053 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.72% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
Exploit availability
Public exploit or proof-of-concept code for CVE-2026-10053 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.
- GitHub PoCPublic proof-of-concept repositories on GitHub reference this CVE.look it up ↗
Advisory coverage (3)
- highCVE-2026-10053: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6,…nvd · 2026-08-23
- criticalGitLab Patch Release: 19.2.2, 19.1.4, 19.0.6gitlab · 2026-08-12
- criticalGitLab Patch Release: 19.2.2, 19.1.4, 19.0.6gitlab · 2026-08-12
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-10053)