Curated summary
GitLab Patch Release: 19.0.2, 18.11.5, 18.10.8 | GitLab Docs
GitLab released patch versions 19.0.2, 18.11.5, and 18.10.8 on June 10, 2026, addressing important security and bug fixes. Self-managed installations should upgrade immediately; GitLab.com is already patched, while GitLab Dedicated customers need no action. The fixes affect both CE and EE and cover account takeover, cross-site scripting, denial of service, authorization bypasses, and server-side request forgery.
Release Scope and Upgrade Guidance
- Affected self-managed installations should upgrade to the latest patch release for their supported GitLab version.
- The releases apply to GitLab Community Edition and Enterprise Edition.
- GitLab publishes:
- Scheduled patch releases twice monthly, on the second and fourth Wednesdays.
- Ad-hoc critical patches for high-severity vulnerabilities.
- Security issues are generally made public on GitLab’s issue tracker 30 days after the release containing their fix.
- GitLab.com has already deployed the patches, and GitLab Dedicated customers do not need to take action.
High-Severity Enterprise Edition Vulnerabilities
CVE-2026-6552 — Group SAML Identity API
- CVSS 8.7.
- An authenticated group Owner could potentially take over another member’s GitLab account through improper authorization.
- Affects GitLab EE versions before 18.10.8, 18.11.5, and 19.0.2.
CVE-2026-10087 — Analytics Dashboard XSS
- CVSS 8.7.
- An authenticated developer could execute arbitrary client-side code on behalf of another user due to inadequate input sanitization.
- Affects EE versions before the patched releases.
CVE-2026-8589 — HTML Injection in Group Settings
- CVSS 7.3.
- Improper sanitization could allow unauthorized email addresses to be added to a targeted user’s account.
- Requires significant privileges and user interaction.
Denial-of-Service Vulnerabilities
CVE-2026-7250 — Grape API JSON Parsing
- CVSS 7.5.
- An unauthenticated attacker could cause denial of service through malformed API request input.
- Affects CE and EE versions dating back to 12.10.
CVE-2026-1500 — Group Placeholder Reassignments API
- CVSS 6.5.
- An authenticated user could trigger uncontrolled resource consumption with a specially crafted file upload.
- Affects CE and EE versions beginning with 17.10.
CVE-2026-10733 — CI/CD Catalog HTML Injection
- CVSS 4.3.
- Improper sanitization could allow an authenticated user to disrupt the CI/CD Catalog page.
Authorization and Data-Access Issues
CVE-2026-6269 — Merge Requests API
- CVSS 5.4.
- Developers could modify hidden merge requests because of incorrect authorization enforcement.
CVE-2026-6277 — Security Inventory
- CVSS 4.3.
- Security Managers could modify project security configuration even when the related feature was disabled.
CVE-2026-6976 — Merge Request Diff
- CVSS 3.7.
- Developers could hide changes from merge request diffs through improperly handled file names.
Server-Side Request Forgery
- CVE-2026-9204 — Gitaly Repository Import
- CVSS 5.3.
- An authenticated user could potentially read arbitrary files from the Gitaly server or access internal network resources during repository import.
- The issue resulted from insufficient validation of secondary URLs.
Recommendation
Administrators of self-managed GitLab instances should upgrade to 19.0.2, 18.11.5, or 18.10.8 as soon as possible, regardless of whether they use Omnibus, source installations, or Helm charts.
Related reading
Continue with another curated summary.