- Sources: patch release, advisory, second advisory
- Summary: GitLab released 19.3.2, 19.2.6 and 19.1.8 on 2026-09-10. The patch fixes CVE-2026-85706, an arbitrary host file read in the repository commits API reachable without authentication, scoring CVSS 10.0 and affecting versions from 18.7 onward. The same release fixes a second Critical, CVE-2026-87719, an insecure deserialization in the GraphQL subscription serializer scoring CVSS 9.9 and affecting Enterprise Edition from 18.3.
- Why it matters: Every self-managed GitLab from 18.7 onward exposes arbitrary host file reads to an unauthenticated caller until it is upgraded, and the patch is two days old.
send feedback on this story