GitLabCVE-2026-87719
GitLab: unsafe deserialization
Critical9.9CVE-2026-87719 · Published Sep 12, 2026 · updated Sep 23, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GitLab Product | >= 18.3, < 18.11.12 | 18.11.12 |
| >= 19.0, < 19.0.9 | 19.0.9 | |
| >= 19.1, < 19.1.8 | 19.1.8 | |
| >= 19.2, < 19.2.6 | 19.2.6 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-502
More GitLab advisories
All GitLab| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 16 | GitLab: race condition | Medium6.4 | 19.1.8+2 more |
| Sep 15 | GitLab: remote code execution | High8.5 | 19.1.8+2 more |
| Sep 15 | GitLab: improper authorization | Medium5.3 | 19.1.8+2 more |
| Sep 15 | GitLab: improper input validation | High7.7 | 19.1.8+2 more |
| Sep 15 | GitLab: missing authentication | Medium5.4 | 19.1.8+2 more |
| Sep 12 | GitLab: missing authentication | Critical10.0 | 18.11.12+3 more |