GitLab released critical security updates for self-managed Community and Enterprise Edition installations, including fixes for two vulnerabilities reported as capable of enabling authenticated remote code execution through malformed regular expressions in CI/CD configuration.
Patch priority
The reported critical issues are tracked as CVE-2026-89078 and CVE-2026-93577 and carry CVSS 9.9 ratings. No active exploitation was confirmed in the reporting, but GitLab urged self-managed customers to update promptly.
What to update
Administrators should move affected installations to 19.4.1, 19.3.3, or 19.2.7, depending on their supported branch. GitLab.com and GitLab Dedicated customers do not need to take manual action for these updates.
Source: SecurityOnline: GitLab critical patch release, linking to GitLab’s patch-release documentation.
