GitLab Patches 8 Vulnerabilities Affecting CE and EE Installations
ID: 8f08ee5a-f9c9-55f8-b3a1-39a6d577125d
STIX ID: report--8f08ee5a-f9c9-55f8-b3a1-39a6d577125d
Feed Name: GBHackers
GitLab published critical security updates (released July 8, 2026) for Community and Enterprise Editions to fix eight vulnerabilities across core features — including a high-severity XSS (CVE-2026-6896, CVSS 8.7), an HTML injection in wiki rendering (CVE-2026-13320, CVSS 7.3), and multiple medium- and low-severity flaws affecting repository mirroring, access controls, and compliance management. Administrators of self-managed deployments are urged to upgrade immediately to versions 19.1.2, 19.0.4, or 18.11.7 because the issues impact a wide range of versions (some as far back as GitLab 9.1); GitLab.com is already patched but unpatched instances remain at risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
