Executive brief
GitLab Enterprise Edition, a platform used by organizations to manage and host software code, contained a flaw in its code review process. Under specific conditions, an authorized user could bypass mandatory security approvals to merge code into protected branches. This could allow unauthorized changes to production software, potentially undermining the integrity of the organization's software supply chain.
Technical details
A race condition (CWE-367) exists in GitLab Enterprise Edition (EE) within the approval rule processing logic for merge requests. An authenticated attacker with network access can exploit this timing issue to merge code into protected branches without satisfying the required approval criteria. The vulnerability affects GitLab EE versions 17.0 through 19.0.5, 19.1 through 19.1.3, and 19.2 through 19.2.1. GitLab has released patches in versions 19.2.1, 19.1.3, and 19.0.5 to address this issue by remediating the race condition in the approval workflow.
Affected products
- GitLab GitLab Enterprise Edition (EE) 17.0 to 19.0.5, 19.1 to 19.1.3, 19.2 to 19.2.1
Timeline
- 2026-07-29: disclosed
- 2026-07-29: patched
- 2026-07-29: advisory