GitLab
GitLab Patch Release: 19.1.2, 19.0.4, 18.11.7
patch-release-gitlab-19-1-2-released Jul 8, 2026 Source: Vendor
Imported by the GitLab patch release catcher from https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/. 8 CVE sections listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
8 lines
Showing 1–8 of 8
CVE-2026-6896
BR2026-0000-008644
unclaimed
Cross-site Scripting issue in vulnerability evidence table renderer impacts GitLab EE
Credited as yvvdwf
CVE-2026-13320
BR2026-0000-008645
unclaimed
HTML Injection in wiki markup rendering impacts GitLab CE/EE
Credited as youzslan
CVE-2026-13320
BR2026-0000-008646
unclaimed
HTML Injection in wiki markup rendering impacts GitLab CE/EE
Credited as a_m_a_m
CVE-2026-11827
BR2026-0000-008647
unclaimed
Insufficiently Protected Credentials issue in repository mirroring impacts GitLab EE
Credited as rogerace
CVE-2026-8472
BR2026-0000-008648
unclaimed
Improper Access Control issue in work items impacts GitLab EE
Credited as go7f0
CVE-2026-7492
BR2026-0000-008649
unclaimed
Missing Authorization issue in commit discussion display impacts GitLab CE/EE
Credited as nathanaelhoun
CVE-2025-12506
BR2026-0000-008650
unclaimed
Ambiguity Reference issue in a tag or branch impacts GitLab CE/EE
Credited as shells3c
CVE-2026-6352
BR2026-0000-008651
unclaimed
Incorrect Authorization issue in compliance violation management impacts GitLab EE
Credited as amanverasia