GitLab released patch versions 19.0.2, 18.11.5, and 18.10.8 on June 10, 2026, addressing 12 security vulnerabilities across CE and EE editions. The most critical fixes include a CVSS 8.7 improper access control flaw in Group SAML Identity API (CVE-2026-6552) that could allow account takeover, a CVSS 8.7 XSS issue in Analytics Dashboard (CVE-2026-10087), and a CVSS 7.5 denial-of-service vulnerability in Grape API JSON parsing (CVE-2026-7250). Additional fixes cover HTML injection, SSRF in Gitaly repository import, authorization bypass in merge request diffs, and more. All self-managed GitLab installations are strongly urged to upgrade immediately. Single-node instances will experience downtime during upgrade; multi-node instances can use zero-downtime procedures.

10m read timeFrom docs.gitlab.com
Post cover image
Table of contents
Security fixesBug fixesImportant notes on upgradingUpdatingReceive patch notifications
851 Impressions