Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5940 articles · 214609 vulns · 37/41 feeds (7d)
← Back to list
9.9
CVE-2026-87719PATCHED
GitLab · GitLab

Deserialization of Untrusted Data in GitLab

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.

Affected Products

VendorProductVersions
GitLabGitLab18.3, 19.2, 19.3

References

  • https://gitlab.com/gitlab-org/gitlab/-/work_items/628160
  • https://hackerone.com/reports/4012289(technical-description, exploit, permissions-required)

Related News (1 articles)

Tier C
VulDB4h ago
CVE-2026-87719 | GitLab EE up to 19.1.7/19.2.5/19.3.1 GraphQL Subscription subscription information disclosure
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
19.1.819.2.619.3.2
CWECWE-502
PublishedSep 12, 2026
Last enriched4h ago
Trending Score41
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-85706EXPKEV
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
Trending: 138
CRITICALCVE-2026-19478
Improper Control of Generation of Code ('Code Injection') in GitLab
Trending: 41
HIGHCVE-2026-19650
Cross-Site Request Forgery (CSRF) in GitLab
Trending: 27
HIGHCVE-2026-18252
Inclusion of Functionality from Untrusted Control Sphere in GitLab
Trending: 5
HIGHCVE-2026-75871
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an a
Trending: 4

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 12, 2026
Discovered by ZDM
Sep 12, 2026
Patch Available
Sep 12, 2026