CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GitLab security advisory (AV26-827)

critical
Serial Number: AV26-827 Date: August 18, 2026 As of August 17, 2026, GitLab is affected by vulnerabilities in the following product: GitLab Prior to 18.11.11 Prior to 19.0.8 Prior to 19.1.6 Prior to 19.2.4 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11 | GitLab Docs GitLab release notes | GitLab Docs

CSIRTS triage

vendor: GitLabproduct: GitLabOtheraffected: <18.11.11, <19.0.8, <19.1.6, <19.2.4
What
GitLab contains one or more critical vulnerabilities across multiple version series.
Who is affected
GitLab deployments on versions before 18.11.11, 19.0.8, 19.1.6, or 19.2.4.
Urgency
Critical; this is marked as a critical patch release requiring immediate remediation.
Action
Update immediately to GitLab 18.11.11, 19.0.8, 19.1.6, or 19.2.4 or later depending on current version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch GitLab

Get an email when a new GitLab advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
critical
Published
2026-08-18
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-827

More from Canadian Centre for Cyber Security