GitLab security advisory (AV26-962)
Canada's Cyber Centre urges GitLab updates to 19.2.7, 19.3.3, or 19.4.1 after a critical patch release.
The Canadian Centre for Cyber Security published advisory AV26-962 on September 25, 2026, saying that as of September 23 GitLab releases before 19.2.7, 19.3.3, and 19.4.1 are affected by vulnerabilities. The notice points to GitLab's critical patch release and release notes and tells administrators to apply the updates. It does not name CVE identifiers or state whether the flaws are being exploited.
- Advisory AV26-962 covers GitLab before 19.2.7, 19.3.3, and 19.4.1.
- GitLab calls the fixes a critical patch release.
- The notice lists no CVE identifiers or exploitation status.
Full article66 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-962
Date: September 25, 2026
As of September 23, 2026, GitLab is affected by vulnerabilities in the following product:
- GitLab
- Prior to 19.2.7
- Prior to 19.3.3
- Prior to 19.4.1
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-962