GitLab
GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5
patch-release-gitlab-19-2-1-released Jul 29, 2026 Source: Vendor
Imported by the GitLab patch release catcher from https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/. 13 CVE sections listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
8 lines
Showing 1–8 of 8
CVE-2026-6267
BR2026-0000-008636
unclaimed
Sensitive Information Exposure issue in Workhorse impacts GitLab CE/EE
Credited as thwin_htet
CVE-2026-12436
BR2026-0000-008637
unclaimed
Mass Assignment issue in Pipeline Schedule API impacts GitLab CE/EE
Credited as a0xnirudh
CVE-2026-6336
BR2026-0000-008638
unclaimed
Improper Access Control issue in project import status impacts GitLab CE/EE
Credited as 3nvz
CVE-2026-14341
BR2026-0000-008639
unclaimed
Improper Authorization issue in project import functionality impacts GitLab CE/EE
Credited as slide123
CVE-2026-3093
BR2026-0000-008640
unclaimed
Cross-site Scripting issue in paginated views impacts GitLab CE/EE
Credited as go7f0
CVE-2026-14351
BR2026-0000-008641
unclaimed
Exposure of Sensitive Information issue in merge request title generation impacts GitLab CE/EE
Credited as toofikz
CVE-2026-4672
BR2026-0000-008642
unclaimed
Improper Access Control issue in Pipeline Test Report API impacts GitLab CE/EE
Credited as rogerace
CVE-2025-14562
BR2026-0000-008643
unclaimed
Incorrect Authorization issue in merge request collaboration settings impacts GitLab CE/EE
Credited as theluci