Vulnerability
Published 2026-09-24
Verified 2026-09-27

GitLab CE/EE CVE-2026-89078 / CVE-2026-93577 (CVSS 9.9): authenticated CI/CD regex → server RCE — patch 19.4.1 / 19.3.3 / 19.2.7

GitLab’s critical patch release (docs: 19.4.1, 19.3.3, 19.2.7) remediates two CVSS 9.9 flaws that let an authenticated user achieve arbitrary code execution on the GitLab server via specially crafted regular expressions in CI/CD configuration. CVE-2026-89078 is a double-free in the regular-expression parser (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L); CVE-2026-93577 is an integer overflow in the regex compiler (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Both affect GitLab CE/EE from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. GitLab.com is already on the fixed build; GitLab Dedicated customers need no action; self-managed admins must upgrade immediately. Reported via HackerOne by joaxcar. Distinct from desk gitlab-email-push-aikido-20260923 (issue-email push path). Primary: GitLab critical patch release notes; wire: Cyber Security News 25 Sep.

Product
GitLab Community Edition / Enterprise Edition (self-managed)
Versions
Affected: 19.2 before 19.2.7; 19.3 before 19.3.3; 19.4 before 19.4.1. Fixed: 19.2.7 / 19.3.3 / 19.4.1. GitLab.com already patched; Dedicated N/A.
CVSS
Exploited in Australia?
unknown
Patch to
Upgrade self-managed GitLab CE/EE to 19.4.1, 19.3.3, or 19.2.7 immediately; review CI/CD permissions for low-privilege accounts that can edit pipeline config; rotate CI/CD variables and deploy tokens if compromise is suspected.

Primary: GitLab Docs — Critical Patch Release: 19.4.1, 19.3.3, 19.2.7 · Vendor: GitLab (vendor patch release notes) · CVE: CVE-2026-89078, CVE-2026-93577 · Cyber Security News — GitLab CI/CD regex RCE (25 Sep 2026)

vulnerabilities cloud identity