Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY1060 SECURITY RECORDS

GitLab

GitLab

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This CVE identity is linked to the Lifecycle record GitLab. Use that record for publisher support phases and retirement dates.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-86341 16 Sep 2026 GitLab: 17.1 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2024-11222 16 Sep 2026 GitLab: 13.0 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2025-14871 16 Sep 2026 GitLab: 18.4.6 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-1168 16 Sep 2026 GitLab: 18.4.6 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-3855 16 Sep 2026 GitLab: 18.2.7 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-7514 16 Sep 2026 GitLab: 13.9 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-8030 16 Sep 2026 GitLab: 13.0 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-16794 16 Sep 2026 GitLab: 18.11 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-19619 16 Sep 2026 GitLab: 19.0 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-78252 16 Sep 2026 GitLab: 15.3 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-79708 16 Sep 2026 GitLab: 19.0 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-12910 15 Sep 2026 GitLab: 18.6 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-13210 15 Sep 2026 GitLab: 15.7 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-82837 15 Sep 2026 GitLab: 10.1.0 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-88765 15 Sep 2026 GitLab: 12.3 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-87719 12 Sep 2026 GitLab: 18.3 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-4398 27 Aug 2026 18.3 < 19.1.7; 19.2 < 19.2.5; 19.3 < 19.3.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-10903 26 Aug 2026 11.10 < 19.1.7; 19.2 < 19.2.5; 19.3 < 19.3.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-3035 26 Aug 2026 11.3 < 19.1.7; 19.2 < 19.2.5; 19.3 < 19.3.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-7487 26 Aug 2026 13.1 < 19.1.7; 19.2 < 19.2.5; 19.3 < 19.3.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-15387 26 Aug 2026 19.1 < 19.1.7; 19.2 < 19.2.5; 19.3 < 19.3.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-18252 26 Aug 2026 18.9 < 19.1.7; 19.2 < 19.2.5; 19.3 < 19.3.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-77801 26 Aug 2026 12.8 < 19.1.7; 19.2 < 19.2.5; 19.3 < 19.3.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-10053 23 Aug 2026 18.8 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-19650 17 Aug 2026 18.2 < 18.11.11; 19.0 < 19.0.8; 19.1 < 19.1.6; 19.2 < 19.2.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-19478 17 Aug 2026 18.2 < 18.11.11; 19.0 < 19.0.8; 19.1 < 19.1.6; 19.2 < 19.2.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-9486 12 Aug 2026 15.6 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-4879 12 Aug 2026 16.0 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-6821 12 Aug 2026 12.0 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-15217 12 Aug 2026 18.2 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-15216 12 Aug 2026 18.2 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-16494 12 Aug 2026 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-18433 12 Aug 2026 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-19228 12 Aug 2026 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-7427 12 Aug 2026 18.5 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-8667 12 Aug 2026 17.6 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-15423 12 Aug 2026 19.0 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-16627 12 Aug 2026 19.2 < 19.2.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-18244 12 Aug 2026 17.7 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-14562 29 Jul 2026 10.6 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-3093 29 Jul 2026 14.0 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-4672 29 Jul 2026 18.4 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-6267 29 Jul 2026 10.1.0 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-6336 29 Jul 2026 16.6 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-12436 29 Jul 2026 18.0 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-13113 29 Jul 2026 17.0 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-14341 29 Jul 2026 12.8 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-14351 29 Jul 2026 8.8 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-15077 29 Jul 2026 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-15831 29 Jul 2026 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.