Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

GitLab

GitLab Patch Release: 19.1.1, 19.0.3, 18.11.6

patch-release-gitlab-19-1-1-released Jun 24, 2026 Source: Vendor

Imported by the GitLab patch release catcher from https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/. 13 CVE sections listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

11 lines
Showing 1–11 of 11
CVE-2026-10086 BR2026-0000-008729 unclaimed
Cross-site Scripting issue in Analytics Dashboard impacts GitLab EE
Credited as yvvdwf
CVE-2026-10712 BR2026-0000-008730 unclaimed
Cross-site Scripting issue in Web IDE workbench asset handler impacts GitLab CE/EE
Credited as joaxcar
CVE-2026-12053 BR2026-0000-008731 unclaimed
Information Disclosure issue in Duo Workflows impacts GitLab EE
Credited as 3nvz
CVE-2026-12053 BR2026-0000-008732 unclaimed
Information Disclosure issue in Duo Workflows impacts GitLab EE
Credited as GitLab team member Dennis Appelt
CVE-2026-5309 BR2026-0000-008733 unclaimed
Authorization Bypass issue in Virtual Registry Cleanup Policy API impacts GitLab EE
Credited as go7f0
CVE-2026-2238 BR2026-0000-008734 unclaimed
Improper Authorization issue in Rapid Diffs impacts GitLab CE/EE
Credited as modhanami
CVE-2026-1606 BR2026-0000-008735 unclaimed
Improper Input Validation issue in Snippets impacts GitLab CE/EE
Credited as st4nly0n
CVE-2026-5952 BR2026-0000-008736 unclaimed
Incorrect Authorization issue in Maven Package Registry impacts GitLab CE/EE
Credited as pkkr
CVE-2026-5796 BR2026-0000-008737 unclaimed
Improper Access Control issue in group packages API impacts GitLab CE/EE
Credited as harshinsecurity
CVE-2026-0934 BR2026-0000-008738 unclaimed
Improper Access Control issue in Protected Environments API impacts GitLab EE
Credited as vulnable
CVE-2026-3176 BR2026-0000-008739 unclaimed
Missing Authorization issue in Security Dashboard impacts GitLab EE
Credited as modestia