GitLab has released critical security updates to address 13 vulnerabilities that could potentially expose sensitive data, manipulate CI/CD pipelines, and disrupt server availability across Community Edition (CE) and Enterprise Edition (EE) deployments.
The latest patch versions, 19.2.1, 19.1.3, and 19.0.5, were released on July 29, 2026. These updates include fixes for high-, medium-, and low-severity issues.
GitLab strongly urges all self-managed users to upgrade immediately, as GitLab.com is already running the patched versions, and GitLab Dedicated customers do not need to take any action.
GitLab Fixes 13 Security Vulnerabilities
Among the most critical vulnerabilities is CVE-2026-6267, which has a high severity level and a CVSS score of 8.5. This flaw affects GitLab Workhorse and could allow authenticated users with Developer-level access to retrieve sensitive information in internal requests due to improper access control.
Another high-risk issue, CVE-2026-12436, allows attackers to exploit a mass-assignment flaw in the Pipeline Schedule API to modify CI/CD configurations belonging to other users, potentially leading to unauthorized pipeline executions.
GitLab has also addressed CVE-2026-15975, a denial-of-service vulnerability that unauthenticated attackers can exploit. By abusing insufficient resource throttling in merge request discussions, attackers may crash or significantly degrade server performance, affecting availability in production environments.
Several medium-severity vulnerabilities impact authorization and access control mechanisms. These include improper authorization in project import functionality, unauthorized access to pipeline test reports, and exposure of confidential issue titles through merge request metadata.
Additionally, a race condition in merge request approval rules could allow code to be merged into protected branches without the necessary approvals, posing a risk to software integrity.
The update also fixes a cross-site scripting issue that could allow the execution of malicious JavaScript through crafted URLs, as well as a prompt injection vulnerability in GitLab Duo Code Review, highlighting emerging risks in AI-assisted development tools. Another issue in Duo Workflows could allow the bypassing of governance controls due to incorrect token generation.
One example of a potential attack scenario involves a low-privilege developer exploiting a flaw in the Pipeline Schedule API to modify scheduled jobs in another project, thereby injecting malicious scripts into the CI/CD pipeline. This could lead to supply chain compromise, unauthorized deployments, or data exfiltration without immediate detection.
GitLab noted that all vulnerabilities will be publicly disclosed 90 days after patches are released, in line with responsible disclosure practices. The company emphasized that keeping installations up to date is critical to protecting sensitive code repositories and development workflows.
CVE IDDescriptionSeverityEditionCVE-2026-6267Workhorse sensitive information exposureHighCE / EECVE-2026-12436Pipeline Schedule API mass assignmentHighCE / EECVE-2026-15975Merge Request Discussions denial of service (DoS)HighCE / EECVE-2026-13113Merge request approval rules race conditionMediumEECVE-2026-16553Virtual Registries credential protection flawMediumEECVE-2026-6336Project import status improper access controlMediumCE / EECVE-2026-14341Project import improper authorizationMediumCE / EECVE-2026-3093Cross-site scripting (XSS) in paginated viewsMediumCE / EECVE-2026-15077Duo Code Review prompt injectionMediumEECVE-2026-15831Duo Workflows security token generation flawMediumEECVE-2026-14351Merge request title information exposureMediumCE / EECVE-2026-4672Pipeline Test Report API improper access controlMediumCE / EECVE-2025-14562Merge request collaboration incorrect authorizationLowCE / EE
The patch release includes database migrations, which may cause downtime for single-node deployments. However, multi-node environments can apply updates using zero-downtime upgrade procedures.
Security teams are advised to prioritize patching, review access controls, and audit CI/CD configurations to mitigate the risk of exploitation associated with these vulnerabilities.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post GitLab Fixes 13 Security Flaws That Can Leak Data, Alter Pipelines, and Crash Servers appeared first on Cyber Security News.



