GitLab
GitLab Patch Release: 19.0.1, 18.11.4, 18.10.7
patch-release-gitlab-19-0-1-released May 27, 2026 Source: Vendor
Imported by the GitLab patch release catcher from https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-0-1-released/. 7 CVE sections listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-0-1-released/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
6 lines
Showing 1–6 of 6
CVE-2026-4868
BR2026-0000-008803
unclaimed
Improper Access Control issue in Duo AI workflow runners impacts GitLab EE
Credited as ahacker1
CVE-2026-1402
BR2026-0000-008804
unclaimed
Denial of Service issue in Wiki impacts GitLab CE/EE
Credited as a92847865
CVE-2026-6713
BR2026-0000-008805
unclaimed
Incorrect Authorization issue in GraphQL WorkItem API impacts GitLab CE/EE
Credited as pollito
CVE-2026-5296
BR2026-0000-008806
unclaimed
Improper Authorization issue in Duo Workflows API impacts GitLab EE
Credited as rogerace
CVE-2026-2601
BR2026-0000-008807
unclaimed
Missing Authorization issue in Operations impacts GitLab EE
Credited as modhanami
CVE-2026-2710
BR2026-0000-008808
unclaimed
Incorrect Authorization issue in certain authentication endpoints impacts GitLab CE/EE
Credited as s4dmach1ne