GitLab Releases Critical Patches Fixing Two Severe RCE Flaws in Self-Managed Instances
GitLab issued a critical security patch on September 23, 2026, addressing 11 vulnerabilities in self-managed instances, including two remote code execution flaws rated 9.9 in severity. The affected CVEs — CVE-2026-89078 and CVE-2026-93577 — involve a double free and integer overflow in regex handling respectively. Administrators should upgrade to version 19.2.7, 19.3.3, or 19.4.1 depending on their current branch, while GitLab.com and GitLab Dedicated users require no action. As an interim measure, admins are advised to restrict web and API access, audit CI/CD permissions, and rotate CI variables on any internet-exposed instances. A ZoomEye scan found over 1.3 million internet-facing GitLab assets as of September 24, 2026, underscoring the urgency of confirming patched versions through the admin area or version endpoint.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in