Intel

AIKIDO-2026-549130

gitlab-ce is vulnerable to Deserialization of Untrusted Data

Deserialization of Untrusted DataCVE-2026-87719 Published 4 days ago

99

Critical Risk

This Affects:

OSgitlab-ce
18.3.0 - 19.1.7
Fixed in 19.1.8
19.2.0 - 19.2.5
Fixed in 19.2.6
19.3.0 - 19.3.1
Fixed in 19.3.2
Are you affected? Scan for Free

TL;DR

The GraphQL subscription serializer accepts crafted subscription arguments that bypass intended serialization and perform server object lookup. An authenticated user with Duo Chat access can obtain Advanced Search instance configurations and sensitive credentials this way. The fix hardens subscription argument handling so deserialization cannot be abused for object lookup.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and Duo Chat is available to users.

Background info

gitlab-ce is vulnerable to Deserialization of Untrusted Data in versions 18.3.0 - 19.1.7, 19.2.0 - 19.2.5 and 19.3.0 - 19.3.1.

How to fix this

Upgrade the gitlab-ce library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform