GitLab has released emergency security updates to fix two critical vulnerabilities that could allow authenticated attackers to execute arbitrary code on vulnerable GitLab servers through specially crafted regular expressions in CI/CD configurations. The flaws, tracked as CVE-2026-89078 and CVE-2026-93577, affect GitLab Community Edition and Enterprise Edition installations. GitLab issued patched releases 19.4.1, 19.3.3, and 19.2.7 on September 23, 2026, and urged administrators of self-managed instances to upgrade immediately. GitLab.com is already running the fixed version, while GitLab Dedicated customers do not need to take action. CVE-2026-89078 is a double-free vulnerability in GitLab’s regular expression parser. Under...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!