GitLab security advisory (AV26-994)
Canadian Cyber Centre advisory urges administrators to patch GitLab AI Gateway flaws fixed in versions 19.2.4, 19.3.2, and 19.4.1.
The Canadian Centre for Cyber Security issued advisory AV26-994 on October 2, 2026, stating GitLab AI Gateway is affected by a vulnerability in versions prior to 19.2.4, 19.3.2, and 19.4.1. Users and administrators are encouraged to review the GitLab release notes and apply updates as they become available. No CVE identifiers or exploitation details were provided in the advisory.
- GitLab AI Gateway vulnerable in versions before 19.2.4, 19.3.2, and 19.4.1.
- Canadian Cyber Centre advisory AV26-994 dated October 2, 2026.
- Administrators urged to apply updates as they become available.
Full article72 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-994
Date: October 2, 2026
As of October 2, 2026, GitLab is affected by a vulnerability in the following product:
- GitLab AI Gateway
- Prior to 19.2.4
- Prior to 19.3.2
- Prior to 19.4.1
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-994