GitLab security advisory (AV26-827) – Update 1
Serial Number: AV26-827 Date: August 18, 2026 Updated: August 21, 2026 As of August 17, 2026, GitLab is affected by vulnerabilities in the following product: GitLab Prior to 18.11.11 Prior to 19.0.8 Prior to 19.1.6 Prior to 19.2.4 Update 1 Open-source reporting indicates that CVE-2026-19478 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11 | GitLab Docs GitLab release notes | GitLab Docs
CSIRTS triage
- What
- GitLab contains one or more critical vulnerabilities across multiple version series.
- Who is affected
- GitLab deployments on versions before 18.11.11, 19.0.8, 19.1.6, or 19.2.4.
- Urgency
- Critical; this is marked as a critical patch release requiring immediate remediation.
- Action
- Update immediately to GitLab 18.11.11, 19.0.8, 19.1.6, or 19.2.4 or later depending on current version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch GitLab
Get an email when a new GitLab advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-827
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-194786.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 93% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-19478 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.ncsc-nl
- critical[NEW] [high] GitLab: Multiple vulnerabilities allow file manipulationcert-bund
- unknownGitLab Multiple Vulnerabilitieshkcert
- unknownNCSC-2026-0303 [1.00] [M/H] Vulnerabilities Fixed in GitLab by GitLab Inc.ncsc-nl
- unknownMultiple vulnerabilities in GitLab (August 18, 2026)cert-fr-avis
- criticalCVE-2026-19478: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.1…nvd
- criticalGitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11gitlab
- criticalGitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11gitlab
More from Canadian Centre for Cyber Security
- unknownSUSE Linux security advisory (AV26-882)2026-09-03
- unknown[Control Systems] Siemens security advisory (AV26-881)2026-09-03
- unknownn8n security advisory (AV26-880)2026-09-03
- unknownAMD security advisory (AV26-879)2026-09-03
- unknownF5 security advisory (AV26-878)2026-09-03