GitLab
GitLab Patch Release: 19.2.2, 19.1.4, 19.0.6
patch-release-gitlab-19-2-2-released Aug 12, 2026 Source: Vendor
Imported by the GitLab patch release catcher from https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/. 14 CVE sections listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
12 lines
Showing 1–12 of 12
CVE-2026-15217
BR2026-0000-007371
unclaimed
Cross-site Scripting issue in Analytics Dashboards table field configuration impacts GitLab CE/EE
Credited as yvvdwf
CVE-2026-15216
BR2026-0000-007372
unclaimed
Cross-site Scripting issue in Analytics Dashboards pagination controls impacts GitLab CE/EE
Credited as yvvdwf
CVE-2026-10053
BR2026-0000-007373
unclaimed
Remote code execution via path traversal in package registry impacts GitLab CE/EE
Credited as invisiblemeerkat
CVE-2026-15423
BR2026-0000-007374
unclaimed
Improper Authorization issue in CI/CD pipeline API impacts GitLab CE/EE
Credited as sim4n6
CVE-2026-16627
BR2026-0000-007375
unclaimed
Cross-site Scripting issue in CI manual job confirmation modal impacts GitLab CE/EE
Credited as 3nvz
CVE-2026-16494
BR2026-0000-007376
unclaimed
Missing Authorization issue in ProjectsController impacts GitLab EE
Credited as 3nvz
CVE-2026-7427
BR2026-0000-007377
unclaimed
Denial of Service issue in GraphQL API JSON parser impacts GitLab CE/EE
Credited as aphantom
CVE-2026-6821
BR2026-0000-007378
unclaimed
Missing Authorization issue in merge requests API impacts GitLab EE
Credited as rogerace
CVE-2026-4879
BR2026-0000-007379
unclaimed
Missing Authorization issue in external status check API impacts GitLab EE
Credited as jaykp
CVE-2026-8667
BR2026-0000-007380
unclaimed
Incorrect Authorization issue in npm dist-tags endpoint impacts GitLab CE/EE
Credited as peppersghost
CVE-2026-18433
BR2026-0000-007381
unclaimed
Incorrect Authorization issue in AI Tool Rules GraphQL resolver impacts GitLab EE
Credited as anshuman_bh
CVE-2025-9486
BR2026-0000-007382
unclaimed
Incorrect Privilege Assignment issue in custom roles impacts GitLab EE
Credited as mateuszek