Key Facts
GitLab released versions 19.3.2, 19.2.6, and 19.1.8 for Community Edition and Enterprise Edition on September 10. The vendor strongly recommends that self-managed installations upgrade immediately; GitLab.com is already running the patched version.
Technical Details
The release lists CVE-2026-85706, a Critical path-traversal issue in the repository commits API affecting GitLab CE/EE, and CVE-2026-87719, a Critical insecure-deserialization issue in the GraphQL subscription serializer affecting GitLab EE. The same release includes additional High-severity fixes.
Impact & Mitigation
Upgrade affected self-managed installations to 19.3.2, 19.2.6, or 19.1.8 according to the supported release branch. Review GitLab’s release notes for deployment-specific guidance and assess exposed instances and sensitive CI/CD secrets while patching.
