CVE & Vulnerabilities · September 26, 2026
GitLab has patched a serious remote-code-execution bug, CVE-2026-89078, caused by a double-free memory error when the server parses a maliciously crafted regular expression inside a CI/CD pipeline configuration. Exploiting it would let a logged-in user run arbitrary code on the GitLab server. The fix landed in GitLab CE/EE releases 19.2.7, 19.3.3, and 19.4.1, so admins on those version branches should upgrade right away.
// source: nvd.nist.gov ↗