GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws
Brief
GitLab has released security updates for Community Edition and Enterprise Edition, addressing 13 vulnerabilities affecting analytics dashboards, CI/CD workflows, APIs, AI services, project settings, and package management.
The company issued GitLab 19.
- 2, 19.
- 4, and 19.
- 6 on August 12, 2026, and strongly advised self-managed customers to upgrade as soon as possible. GitLab. com is already patched, while GitLab Dedicated customers do not need to take action.
The update addresses six high-severity flaws, six medium-severity flaws, and one low-severity issue. The most serious problems include three cross-site scripting vulnerabilities and multiple authorization weaknesses that could let authenticated users perform actions beyond their intended permissions.
