FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Gitlab -- vulnerabilities

Affected packages
19.4.0 <= gitlab-ce < 19.4.1
19.3.0 <= gitlab-ce < 19.3.3
13.11.0 <= gitlab-ce < 19.2.7
19.4.0 <= gitlab-ee < 19.4.1
19.3.0 <= gitlab-ee < 19.3.3
13.11.0 <= gitlab-ee < 19.2.7

Details

VuXML ID 3f11e437-b7cd-11f1-a883-2cf05da270f3
Discovery 2026-09-23
Entry 2026-09-24

Gitlab reports:

Double Free issue in Regular Expression Parser impacts GitLab CE/EE

Integer Overflow issue in Regular Expression Compiler impacts GitLab CE/EE

Cross-site Scripting issue in merge request diff viewer impacts GitLab CE/EE

Missing Authorization issue in Duo AI job troubleshooting feature impacts GitLab EE

Incorrect Authorization issue in MCP API scope enforcement impacts GitLab CE/EE

Use of Less Trusted Source issue in Direct Transfer import user mapping impacts GitLab CE/EE

Missing Authorization issue in Epic Issues REST API impacts GitLab CE/EE

Incorrect Authorization issue in Duo Workflow Service token governance enforcement impacts GitLab EE

Improper Access Control issue in GraphQL memberRoles dependentSecurityPolicies resolver impacts GitLab EE

Missing Authorization issue in GraphQL CI job trace API impacts GitLab CE/EE

Race Condition issue in MCP gitlab_search tool impacts GitLab CE/EE

References

CVE Name CVE-2026-10518
CVE Name CVE-2026-4523
CVE Name CVE-2026-84739
CVE Name CVE-2026-89078
CVE Name CVE-2026-8937
CVE Name CVE-2026-92470
CVE Name CVE-2026-92529
CVE Name CVE-2026-92530
CVE Name CVE-2026-92628
CVE Name CVE-2026-92874
CVE Name CVE-2026-93577
URL https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/?nav=19.4.1