CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GitLab Patch Release: 18.11.8

unknown
On August 5, 2026, we released versions 18.11.8 for GitLab Community Edition and Enterprise Edition. These versions resolve a number of regressions and bugs. This patch release does not include any security fixes. GitLab Community Edition and Enterprise Edition 18.11.8 Update gitlab-logger to v4.0.1 (18-11-stable) Backport of ‘Keep virtual registry settings toggle visible when disabled’ into 18.11 Backport of “Fix blob preview diff hiding blank added lines” Backport of ‘Backfill duo_secret_detection_fp_enabled to false’ [18.11] Backport of “Remove –unlink-first and –recursive-unlink from tar extract” Backport of ‘Add postgres_index_bloat_estimate SQL function’ [18.11 Backport] Bump PostgreSQL versions to 16.14 and 17.10 Backport fix for Mattermost deprecation to 18.11 Important notes on upgrading This patch includes database migrations that may impact your upgrade process. Postgresql server versions were updated to 16.14 and 17.10 to include the latest upstream patches and fixes. This version fixes an issue where upgrading to 19.x failed with a Mattermost deprecation error for Linux package installations, even when Mattermost was not actively configured. Upgrade to this version before upgrading to 19.0 or later. For details, see Mattermost removed from the Linux package . On very large installations, the gitlab:db:reindex task could time out while estimating index bloat for a single index, causing the job to fail repeatedly and leaving PostgreSQL indexes to grow increasingly bloated, which in turn degraded overall instance performance and complicated upgrades. This release restructures the bloat-estimation query for single-index lookups, restoring reliable automatic reindexing on large databases. Impact on your installation: Single-node instances : This patch will cause downtime during the upgrade as migrations must complete before GitLab can start. Multi-node instances : With proper zero-downtime upgrade procedures , this patch can be applied without downtime. Regu

CSIRTS triage

What
Bug fix and regression resolution release with no security fixes.
Who is affected
GitLab Community Edition and Enterprise Edition 18.11.x deployments.
Urgency
Low; this is a maintenance release with no security content.
Action
Update to version 18.11.8 when convenient, noting database migrations may impact upgrade process.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch GitLab Community Edition and Enterprise Edition

Get an email when a new GitLab Community Edition and Enterprise Edition advisory drops — max one per day, one-click unsubscribe.

Details

Source
GitLab Security Releases (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-05
Exploitation
Not in CISA KEV at last sync

Original advisory: https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-11-8-released/

More from GitLab Security Releases