CISA listed GitLab's CVSS 10.0 path traversal on September 11, 2026. GitLab fixed 19.3, 19.2 and 19.1 only; 19.0 and every 18.x line are affected with no…
Every affected line against the fix list
| Line | First release | Security support ends | Fixed build | Position |
|---|---|---|---|---|
| 19.3 | August 20, 2026 | November 19, 2026 | 19.3.2 | Current stable |
| 19.2 | July 16, 2026 | October 15, 2026 | 19.2.6 | Maintained |
| 19.1 | June 18, 2026 | September 17, 2026 | 19.1.8 | Maintained until 19.4 ships |
| 19.0 | May 21, 2026 | August 20, 2026 | None | Affected, unsupported |
| 18.11 | April 16, 2026 | July 16, 2026 | None | Affected, unsupported |
| 18.10 | March 19, 2026 | June 18, 2026 | None | Affected, unsupported |
| 18.9 | February 19, 2026 | May 21, 2026 | None | Affected, unsupported |
| 18.8 | January 15, 2026 | April 16, 2026 | None | Affected, unsupported |
| 18.7 | December 18, 2025 | March 19, 2026 | None | Affected, unsupported |
What's covered
- What the flaw is
- Every affected line against the fix list
- The 19.1 trap
- What to do, by line
Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-gitlab-cve-2026-85706-six-lines-without-a-fix
Top comments (0)