GitLab July 2026 Security Release Patches 13 Vulnerabilities Including Unauthenticated DoS, CI/CD Tampering, and AI Prompt Injection (CVE-2026-15975 and Others)
Scope: GitLab Community Edition and Enterprise Edition Versions 11.8 through 19.2.0 (Self-Managed Deployments Only)
Severity: High
GitLab released security updates on July 29, 2026, addressing 13 vulnerabilities across CE and EE spanning denial of service, data exposure, CI/CD pipeline manipulation, and AI prompt injection, with three rated high severity. CVE-2026-15975 (CVSS 7.5) allows unauthenticated attackers to crash or severely degrade self-managed GitLab instances by sending crafted requests to the merge request discussion endpoint with no credentials required. CVE-2026-6267 (CVSS 8.5) allows authenticated Developer-level users to retrieve unauthorized data from GitLab Workhorse internal request handling. CVE-2026-12436 (CVSS 8.4) enables pipeline schedule configuration tampering across other users' projects. Additionally, a race condition in merge request approval rules (CVE-2026-13113) can allow code to be merged into protected branches without the required approvals, and a prompt injection flaw in GitLab Duo Code Review highlights emerging AI attack surfaces in development tooling. GitLab.com and GitLab Dedicated are already patched and require no action; all self-managed instance administrators must upgrade to versions 19.2.1, 19.1.3, or 19.0.5 immediately.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.