Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-89078: GitLab allows logged-in user to run code on server

CVE-2026-89078 · published 16 days ago
Summary

Versions of GitLab Community and Enterprise Edition released before 19.2.7, 19.3.3, and 19.4.1 have a flaw that could let a signed‑in user cause the server to execute their own code. The problem occurs when a specially crafted pattern is used in a CI/CD configuration. Update GitLab to the latest release that includes the fix, or apply the provided patches, to remove the risk.

What to do
  • Update gitlab to version 19.4.1.
Affected software
Ecosystem VendorProductAffected versions
– gitlab gitlab < 19.2.7
>= 19.2.0, < 19.2.7
>= 19.3.0, < 19.3.3
19.4.0
Bitnami – gitlab >= 19.4.0, < 19.4.1
Fix: upgrade to 19.4.1
Original advisory text
Double Free in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.9 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-415Double Free
Timeline
Published24 Sep 2026
Updated9 Oct 2026
First seen23 Sep 2026
Sources
CVE-2026-89078 · MITRE
Track software like this
Free during beta