Executive brief
GitLab has fixed a high-severity security flaw in its Workhorse component, which manages large file transfers and internal requests. An authenticated user with Developer-level access could have exploited this issue to bypass access controls and view sensitive information they were not authorized to see. This could lead to the exposure of proprietary code or internal configuration data. Organizations using self-managed GitLab instances should upgrade to the latest patched versions immediately to protect their data.
Technical details
A sensitive information exposure vulnerability exists in GitLab Workhorse due to insufficient access controls on internal request handling. The flaw (CWE-201) allows an authenticated attacker with at least Developer-level privileges to craft requests that bypass intended authorization checks, potentially leading to the disclosure of sensitive internal data. The attack vector is network-based with high complexity, requiring specific conditions to be met for successful exploitation. GitLab has released patches in versions 19.0.5, 19.1.3, and 19.2.1 to address this issue. The vulnerability was reported via the HackerOne bug bounty program.
Affected products
- GitLab GitLab CE/EE 10.1.0 to 19.0.5, 19.1 to 19.1.3, 19.2 to 19.2.1
Timeline
- 2026-07-29: advisory: GitLab released security patches and advisory.
- 2026-07-29: patched: GitLab.com was updated and self-managed patches were released.