GitLab patches critical CI/CD regex code-execution flaws
GitLab fixed two CVSS 9.9 CI/CD regex flaws in 19.2.7, 19.3.3, and 19.4.1; Canada urged the same updates.
GitLab issued an emergency critical patch for two CVSS 9.9 flaws, CVE-2026-89078 and CVE-2026-93577, that let an authenticated user place a crafted regular expression in a CI/CD configuration and potentially execute code on the server via a double-free or an integer overflow. Self-managed GitLab CE and EE 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 are affected; the fixes are 19.2.7, 19.3.3, and 19.4.1, and GitLab.com is already patched. The same update also addresses high-severity XSS CVE-2026-84739 and authorization flaw CVE-2026-92470 in GitLab Duo AI job troubleshooting. On September 25, 2026, the Canadian Centre for Cyber Security published advisory AV26-962, stating that as of September 23 those pre-patch releases are affected and directing administrators to GitLab's critical patch and release notes. The Canadian notice does not name CVE identifiers or say whether the flaws are being exploited, so it is less specific than the vulnerability report but agrees on the fixed versions.
- GitLab patched CVE-2026-89078 (double-free in the regex parser, CVSS 9.9) and CVE-2026-93577 (integer overflow in the regex compiler, CVSS 9.9).
- An authenticated user can place a crafted regular expression in a CI/CD configuration to trigger either flaw and potentially execute code on self-managed GitLab CE and EE.
- Affected releases are GitLab CE and EE 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1; fixes are 19.2.7, 19.3.3, and 19.4.1, and GitLab.com is already patched.
- The same release also fixes high-severity XSS CVE-2026-84739 and Duo AI job-troubleshooting authorization flaw CVE-2026-92470.
- Canada's Cyber Centre advisory AV26-962 (September 25, 2026) says that as of September 23 releases before those versions are affected and urges administrators to update.
- AV26-962 names no CVE identifiers and does not state whether the flaws are being exploited.
Coverage timelineoldest first · each row is one article
- · 1d agoCritical GitLab Bugs Let Attackers Execute Code Through Malicious CI/CD Regex
Cyber Security News· 74
GitLab patched two CVSS 9.9 flaws letting authenticated users execute code via malicious CI/CD regular expressions.
- · 1d agoGitLab security advisory (AV26-962)
Canadian Centre for Cyber Security· 56
Canada's Cyber Centre urges GitLab updates to 19.2.7, 19.3.3, or 19.4.1 after a critical patch release.
Vulnerabilities in this storyAll →
- published —
- CVE-2026-890789.9—Authenticated RCE in GitLab CE/EE via Double Free in CI/CD Regex Parsingpublished · GitLab Community Edition (CE)+1 related