Multiple vulnerabilities in GitLab (August 26, 2026)
Multiple vulnerabilities have been discovered in GitLab. Some of them allow an attacker to cause remote arbitrary code execution, remote denial of service and data confidentiality breach.
CSIRTS triage
- What
- Multiple vulnerabilities in GitLab including remote arbitrary code execution, denial of service, and data confidentiality breaches.
- Who is affected
- GitLab installations.
- Urgency
- High; active RCE and data breach vectors present.
- Action
- Immediately apply GitLab security patches to affected versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch GitLab
Get an email when a new GitLab advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1086/
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-4398 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15387 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-10903 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18252 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7487 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-77801 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-3035 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- lowCVE-2026-7487: GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.…nvd
- mediumCVE-2026-77801: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.1.7,…nvd
- mediumCVE-2026-3035: GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.…nvd
- highCVE-2026-18252: GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19…nvd
- mediumCVE-2026-15387: GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19…nvd
- mediumCVE-2025-10903: GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 1…nvd
- high[NEW] [high] GitLab: Multiple vulnerabilitiescert-bund
- criticalGitLab Patch Release: 19.3.1, 19.2.5, 19.1.7gitlab
Recent advisories for GitLab
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- lowCVE-2026-7487: GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.…nvd · 2026-08-26
- mediumCVE-2026-77801: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.1.7,…nvd · 2026-08-26
- mediumCVE-2026-3035: GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.…nvd · 2026-08-26
- highCVE-2026-18252: GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19…nvd · 2026-08-26
- mediumCVE-2026-15387: GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19…nvd · 2026-08-26
- mediumCVE-2025-10903: GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 1…nvd · 2026-08-26
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Google Chrome (August 26, 2026)2026-08-26
- unknownMultiple vulnerabilities in Apache Tomcat (August 26, 2026)2026-08-26
- unknownMultiple vulnerabilities in Veeam products (August 26, 2026)2026-08-26
- unknownVulnerability in Apereo CAS (August 26, 2026)2026-08-26
- unknownMultiple vulnerabilities in OpenSSL (August 26, 2026)2026-08-26