GitLab released patch versions 19.0.1, 18.11.4, and 18.10.7 for Community and Enterprise Editions on May 27, 2026. The release addresses 7 CVEs including a high-severity improper access control flaw (CVSS 8.2) in Duo AI workflow runners that could allow identity spoofing, a denial-of-service issue in Wiki (CVSS 6.5), and several authorization bypass vulnerabilities in GraphQL, Pipelines, and authentication endpoints. Self-managed GitLab installations are strongly urged to upgrade immediately. The patches also include numerous bug fixes across all three versions.

8m read timeFrom docs.gitlab.com
Post cover image
Table of contents
Security fixesBug fixesImportant notes on upgradingUpdatingReceive Patch Notifications
146 Impressions