Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY1071 SECURITY RECORDS

GitLab

GitLab

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This CVE identity is linked to the Lifecycle record GitLab. Use that record for publisher support phases and retirement dates.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-4523 29 Sep 2026 GitLab: 15.11 < 19.2.7, 19.3 < 19.3.3, 19.4 < 19.4.1 Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above. Update reference ↗
CVE-2026-8937 29 Sep 2026 GitLab: 19.0 < 19.2.7, 19.3 < 19.3.3, 19.4 < 19.4.1 Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above. Update reference ↗
CVE-2026-10518 29 Sep 2026 GitLab: 17.9 < 19.2.7, 19.3 < 19.3.3, 19.4 < 19.4.1 Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above. Update reference ↗
CVE-2026-84739 29 Sep 2026 GitLab: 13.11 < 19.2.7, 19.3 < 19.3.3, 19.4 < 19.4.1 Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above. Update reference ↗
CVE-2026-89078 23 Sep 2026 GitLab: 19.2 < 19.2.7, 19.3 < 19.3.3, 19.4 < 19.4.1 Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above. Update reference ↗
CVE-2026-92530 23 Sep 2026 GitLab: 19.1 < 19.2.7, 19.3 < 19.3.3, 19.4 < 19.4.1 Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above. Update reference ↗
CVE-2026-92470 23 Sep 2026 GitLab: 18.7 < 19.2.7, 19.3 < 19.3.3, 19.4 < 19.4.1 Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above. Update reference ↗
CVE-2026-92529 23 Sep 2026 GitLab: 19.1 < 19.2.7, 19.3 < 19.3.3, 19.4 < 19.4.1 Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above. Update reference ↗
CVE-2026-92874 23 Sep 2026 GitLab: 18.3 < 19.2.7, 19.3 < 19.3.3, 19.4 < 19.4.1 Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above. Update reference ↗
CVE-2026-92628 23 Sep 2026 GitLab: 18.6 < 19.2.7, 19.3 < 19.3.3, 19.4 < 19.4.1 Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above. Update reference ↗
CVE-2026-93577 23 Sep 2026 GitLab: 19.2 < 19.2.7, 19.3 < 19.3.3, 19.4 < 19.4.1 Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above. Update reference ↗
CVE-2026-86341 16 Sep 2026 GitLab: 17.1 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2024-11222 16 Sep 2026 GitLab: 13.0 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2025-14871 16 Sep 2026 GitLab: 18.4.6 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-1168 16 Sep 2026 GitLab: 18.4.6 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-3855 16 Sep 2026 GitLab: 18.2.7 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-7514 16 Sep 2026 GitLab: 13.9 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-8030 16 Sep 2026 GitLab: 13.0 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-16794 16 Sep 2026 GitLab: 18.11 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-19619 16 Sep 2026 GitLab: 19.0 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-78252 16 Sep 2026 GitLab: 15.3 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-79708 16 Sep 2026 GitLab: 19.0 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-12910 15 Sep 2026 GitLab: 18.6 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-13210 15 Sep 2026 GitLab: 15.7 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-82837 15 Sep 2026 GitLab: 10.1.0 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-88765 15 Sep 2026 GitLab: 12.3 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-87719 12 Sep 2026 GitLab: 18.3 < 18.11.12, 19.0 < 19.0.9, 19.1 < 19.1.8, 19.2 < 19.2.6, 19.3 < 19.3.2 Upgrade to versions 18.11.12, 19.0.9, 19.1.8, 19.2.6, 19.3.2 or above. Update reference ↗
CVE-2026-4398 27 Aug 2026 GitLab: 18.3 < 19.1.7, 19.2 < 19.2.5, 19.3 < 19.3.1 Upgrade to versions 19.1.7, 19.2.5, 19.3.1 or above. Update reference ↗
CVE-2025-10903 26 Aug 2026 11.10 < 19.1.7; 19.2 < 19.2.5; 19.3 < 19.3.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-3035 26 Aug 2026 11.3 < 19.1.7; 19.2 < 19.2.5; 19.3 < 19.3.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-7487 26 Aug 2026 13.1 < 19.1.7; 19.2 < 19.2.5; 19.3 < 19.3.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-15387 26 Aug 2026 19.1 < 19.1.7; 19.2 < 19.2.5; 19.3 < 19.3.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-18252 26 Aug 2026 18.9 < 19.1.7; 19.2 < 19.2.5; 19.3 < 19.3.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-77801 26 Aug 2026 12.8 < 19.1.7; 19.2 < 19.2.5; 19.3 < 19.3.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-10053 23 Aug 2026 18.8 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-19650 17 Aug 2026 18.2 < 18.11.11; 19.0 < 19.0.8; 19.1 < 19.1.6; 19.2 < 19.2.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-19478 17 Aug 2026 18.2 < 18.11.11; 19.0 < 19.0.8; 19.1 < 19.1.6; 19.2 < 19.2.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-9486 12 Aug 2026 GitLab: 15.6 < 19.0.6, 19.1 < 19.1.4, 19.2 < 19.2.2 Upgrade to versions 19.0.6, 19.1.4, 19.2.2 or above. Update reference ↗
CVE-2026-4879 12 Aug 2026 16.0 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-6821 12 Aug 2026 12.0 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-15217 12 Aug 2026 18.2 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-15216 12 Aug 2026 18.2 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-16494 12 Aug 2026 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-18433 12 Aug 2026 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-19228 12 Aug 2026 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-7427 12 Aug 2026 18.5 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-8667 12 Aug 2026 17.6 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-15423 12 Aug 2026 19.0 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-16627 12 Aug 2026 19.2 < 19.2.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-18244 12 Aug 2026 17.7 < 19.0.6; 19.1 < 19.1.4; 19.2 < 19.2.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.