Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-89078: GitLab allows logged-in user to run code on server
CVE-2026-89078 · published 16 days ago
Summary
Versions of GitLab Community and Enterprise Edition released before 19.2.7, 19.3.3, and 19.4.1 have a flaw that could let a signed‑in user cause the server to execute their own code. The problem occurs when a specially crafted pattern is used in a CI/CD configuration. Update GitLab to the latest release that includes the fix, or apply the provided patches, to remove the risk.
What to do
- Update gitlab to version 19.4.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | gitlab | gitlab |
< 19.2.7 >= 19.2.0, < 19.2.7 >= 19.3.0, < 19.3.3 19.4.0 |
| Bitnami | – | gitlab |
>= 19.4.0, < 19.4.1 Fix: upgrade to 19.4.1
|
Original advisory text
Double Free in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration.
References
- https://gitlab.com/gitlab-org/gitlab/-/work_items/628577 Issue Tracking
- https://hackerone.com/reports/4019059 Permissions Required
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/ Release Notes Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-89078 URL
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-415Double Free
Timeline
Published24 Sep 2026
Updated9 Oct 2026
First seen23 Sep 2026
Track software like this
Free during beta