Multiple vulnerabilities in GitLab (August 26, 2026)
Multiple vulnerabilities have been discovered in GitLab. Some of them allow an attacker to cause remote arbitrary code execution, remote denial of service and data confidentiality breach.
CSIRTS triage
- What
- Multiple vulnerabilities in GitLab including remote arbitrary code execution, denial of service, and data confidentiality breaches.
- Who is affected
- GitLab installations.
- Urgency
- High; active RCE and data breach vectors present.
- Action
- Immediately apply GitLab security patches to affected versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch GitLab
Get an email when a new GitLab advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1086/
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-4398 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15387 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-10903 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18252 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7487 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-77801 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-3035 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] GitLab: Multiple vulnerabilitiescert-bund
- lowCVE-2026-7487: GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.…nvd
- mediumCVE-2026-77801: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.1.7,…nvd
- mediumCVE-2026-3035: GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.…nvd
- highCVE-2026-18252: GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19…nvd
- mediumCVE-2026-15387: GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19…nvd
- mediumCVE-2025-10903: GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 1…nvd
- criticalGitLab Patch Release: 19.3.1, 19.2.5, 19.1.7gitlab
Recent advisories for GitLab
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-84664: Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection confi…nvd · 2026-09-02
- highCVE-2026-82289: Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any …nvd · 2026-08-28
- high[NEW] [high] GitLab: Multiple vulnerabilitiescert-bund · 2026-08-28
- highCVE-2026-75871: GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all version…nvd · 2026-08-27
- highCVE-2026-19889: GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all version…nvd · 2026-08-27
- lowCVE-2026-7487: GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.…nvd · 2026-08-26
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Sonicwall Network Security Manager (September 4, 2026)2026-09-04
- unknownMultiple vulnerabilities in Debian Linux kernel (September 4, 2026)2026-09-04
- unknownMultiple vulnerabilities in VMware products (September 4, 2026)2026-09-04
- unknownMultiple vulnerabilities in Elastic Kibana (September 4, 2026)2026-09-04
- unknownMultiple vulnerabilities in Google Chrome (September 4, 2026)2026-09-04