Skip to content
gitlabCVE-2026-3855

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.

Low3.1CVE-2026-3855 · Published Sep 16, 2026

Source advisory

Affected versions

PackageAffectedFixed in
GitLab
Vendor
>= 18.2.7, < 19.1.819.1.8
>= 19.2, < 19.2.619.2.6
>= 19.3, < 19.3.219.3.2
Details and references

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user with project-level permissions to access restricted file contents on the server or cause denial of service due to improper validation of parameters in the Terraform state upload functionality.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
no source yet
Weakness
CWE-99

More gitlab advisories

All
DateAdvisory
Sep 15GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.
CVE-2026-88765High8.5fixed in GitLab 19.1.8, GitLab 19.2.6, GitLab 19.3.2
Sep 15GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.
CVE-2026-82837Medium5.3fixed in GitLab 19.1.8, GitLab 19.2.6, GitLab 19.3.2
Sep 15GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.
CVE-2026-12910Medium5.4fixed in GitLab 19.1.8, GitLab 19.2.6, GitLab 19.3.2
Sep 15GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.
CVE-2026-13210High7.7fixed in GitLab 19.1.8, GitLab 19.2.6, GitLab 19.3.2
Sep 16GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.
CVE-2024-11222Medium6.4fixed in GitLab 19.1.8, GitLab 19.2.6, GitLab 19.3.2
Sep 16GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.
CVE-2025-14871High7.5fixed in GitLab 19.1.8, GitLab 19.2.6, GitLab 19.3.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.