GitLabCVE-2026-88765
GitLab: remote code execution
High8.5CVE-2026-88765 · Published Sep 15, 2026 · updated Sep 16, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a specially crafted Git project export to overflow the Unicode conversion buffer used in Advanced Search indexing.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GitLab Product | >= 12.3, < 19.1.8 | 19.1.8 |
| >= 19.2, < 19.2.6 | 19.2.6 | |
| >= 19.3, < 19.3.2 | 19.3.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-77
More GitLab advisories
All GitLab| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 16 | GitLab: improper authorization | Medium4.3 | 19.1.8+2 more |
| Sep 16 | GitLab: denial of service | High7.5 | 19.1.8+2 more |
| Sep 16 | GitLab: race condition | Medium6.4 | 19.1.8+2 more |
| Sep 15 | GitLab: improper authorization | Medium5.3 | 19.1.8+2 more |
| Sep 15 | GitLab: missing authentication | Medium5.4 | 19.1.8+2 more |
| Sep 15 | GitLab: improper input validation | High7.7 | 19.1.8+2 more |