<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/gitlab-critical-patch-release-19-3-2-19-2-6-19-1-8-1mf9ovdpq" -->

---
title: GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8
description: GitLab shipped critical patch releases 19.3.2, 19.2.6, and 19.1.8 for Community and Enterprise Edition, addressing 17 security vulnerabilities. The most severe...
canonical: https://daily.dev/posts/gitlab-critical-patch-release-19-3-2-19-2-6-19-1-8-1mf9ovdpq
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8 | daily.dev
og:description: GitLab shipped critical patch releases 19.3.2, 19.2.6, and 19.1.8 for Community and Enterprise Edition, addressing 17 security vulnerabilities. The most severe...
og:url: https://daily.dev/posts/gitlab-critical-patch-release-19-3-2-19-2-6-19-1-8-1mf9ovdpq
og:image: https://api.daily.dev/og/posts/1MF9OVDpQ.png
og:image:alt: GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8

**[GitLab](https://daily.dev/sources/gitlab)** · 13 min read · 2 upvotes · 0 comments

## Summary

GitLab shipped critical patch releases 19.3.2, 19.2.6, and 19.1.8 for Community and Enterprise Edition, addressing 17 security vulnerabilities. The most severe is a CVSS 10.0 unauthenticated path traversal issue in the repository commits API allowing arbitrary file reads, alongside a 9.9 CVSS insecure deserialization flaw exposing Advanced Search credentials via GraphQL, and an 8.5 CVSS buffer overflow enabling remote code execution through crafted Git project imports. Other fixes address CI/CD variable scope bypasses, XSS in the Markdown table renderer and Content Editor, SAML SSO bypass, credential exposure via Workhorse, and several authorization bypasses in protected environment approvals and compliance frameworks. GitLab.com is already patched; self-managed installations are strongly urged to upgrade immediately. The releases also bump dependencies including Go, Ruby, PostgreSQL, Redis, NGINX, and Consul, and include database migrations that may cause downtime on single-node instances.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released>

## Questions this post answers

### What is the critical vulnerability fixed in GitLab 19.3.2, 19.2.6, and 19.1.8?

The most critical is CVE-2026-85706, a path traversal issue in the repository commits API with a CVSS score of 10.0, allowing an unauthenticated user to read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement. It affects GitLab CE/EE versions from 18.7 up to the patched releases.

_Teams tracking severe GitLab CVEs can follow patch coverage like this on daily.dev._

### Do I need downtime to upgrade to GitLab 19.3.2?

Single-node GitLab instances will experience downtime during the upgrade because database migrations must complete before GitLab can start, while multi-node instances can apply the patch without downtime by following proper zero-downtime upgrade procedures. Version 19.3.2 also includes post-deploy migrations that run after the upgrade completes.

_Planning a GitLab upgrade window is easier when daily.dev surfaces release details like these._

### What vulnerability affects GitLab's GraphQL subscription serializer in version 19.2.6?

CVE-2026-87719 is an insecure deserialization issue in the GraphQL subscription serializer with a CVSS score of 9.9, allowing an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument. It affects GitLab EE versions from 18.3 up to the patched releases and is fixed in 19.1.8, 19.2.6, and 19.3.2.

_Developers auditing GraphQL-related CVEs can keep tabs on fixes like this via daily.dev._

## Similar posts on daily.dev

- [GitLab Patch Release: 19.0.2, 18.11.5, 18.10.8](https://daily.dev/posts/gitlab-patch-release-19-0-2-18-11-5-18-10-8-fmukjse7k) · GitLab · 0 upvotes · 0 comments
- [GitLab Patch Release: 19.0.1, 18.11.4, 18.10.7](https://daily.dev/posts/gitlab-patch-release-19-0-1-18-11-4-18-10-7-zr6cdslky) · GitLab · 0 upvotes · 0 comments
- [GitLab Patch Release: 19.1.1, 19.0.3, 18.11.6](https://daily.dev/posts/gitlab-patch-release-19-1-1-19-0-3-18-11-6-flm7cmppy) · GitLab · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cicd](https://daily.dev/tags/cicd), [#graphql](https://daily.dev/tags/graphql), [#gitlab](https://daily.dev/tags/gitlab)

[View this post on daily.dev](https://daily.dev/posts/gitlab-critical-patch-release-19-3-2-19-2-6-19-1-8-1mf9ovdpq)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8","url":"https://daily.dev/posts/gitlab-critical-patch-release-19-3-2-19-2-6-19-1-8-1mf9ovdpq","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/gitlab-critical-patch-release-19-3-2-19-2-6-19-1-8-1mf9ovdpq"},"datePublished":"2026-09-11T11:45:50.381Z","dateModified":"2026-09-15T00:55:52.262Z","description":"GitLab shipped critical patch releases 19.3.2, 19.2.6, and 19.1.8 for Community and Enterprise Edition, addressing 17 security vulnerabilities. The most severe...","image":"https://media.daily.dev/image/upload/s--HRgLpUt6--/f_auto/v1722860399/public/Placeholder%2003","thumbnailUrl":"https://media.daily.dev/image/upload/s--HRgLpUt6--/f_auto/v1722860399/public/Placeholder%2003","isAccessibleForFree":true,"articleSection":"GitLab","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"GitLab","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/3720ce340ca4435daef529abbf361b69","url":"https://daily.dev/sources/gitlab"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/gitlab-critical-patch-release-19-3-2-19-2-6-19-1-8-1mf9ovdpq","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cicd,graphql,gitlab","timeRequired":"PT13M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"GitLab","item":"https://daily.dev/sources/gitlab"},{"@type":"ListItem","position":3,"name":"GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/gitlab-critical-patch-release-19-3-2-19-2-6-19-1-8-1mf9ovdpq#faq","mainEntity":[{"@type":"Question","name":"What is the critical vulnerability fixed in GitLab 19.3.2, 19.2.6, and 19.1.8?","acceptedAnswer":{"@type":"Answer","text":"The most critical is CVE-2026-85706, a path traversal issue in the repository commits API with a CVSS score of 10.0, allowing an unauthenticated user to read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement. It affects GitLab CE/EE versions from 18.7 up to the patched releases. Teams tracking severe GitLab CVEs can follow patch coverage like this on daily.dev."}},{"@type":"Question","name":"Do I need downtime to upgrade to GitLab 19.3.2?","acceptedAnswer":{"@type":"Answer","text":"Single-node GitLab instances will experience downtime during the upgrade because database migrations must complete before GitLab can start, while multi-node instances can apply the patch without downtime by following proper zero-downtime upgrade procedures. Version 19.3.2 also includes post-deploy migrations that run after the upgrade completes. Planning a GitLab upgrade window is easier when daily.dev surfaces release details like these."}},{"@type":"Question","name":"What vulnerability affects GitLab's GraphQL subscription serializer in version 19.2.6?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-87719 is an insecure deserialization issue in the GraphQL subscription serializer with a CVSS score of 9.9, allowing an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument. It affects GitLab EE versions from 18.3 up to the patched releases and is fixed in 19.1.8, 19.2.6, and 19.3.2. Developers auditing GraphQL-related CVEs can keep tabs on fixes like this via daily.dev."}}]}
```

