DIRAS TAKE
Urgent: public exploit code exists, so prioritize updating exposed GitLab instances to the fixed releases listed by GitLab or immediately restrict access to the package registry and monitor for suspicious activity.
What is CVE-2026-10053?
An authenticated user can execute arbitrary code on GitLab via a path traversal flaw in the package registry; this issue is tracked as CVE-2026-10053. The vulnerability affects GitLab CE/EE versions 18.8 up to but not including 19.0.6, 19.1 up to but not including 19.1.4, and 19.2 up to but not including 19.2.2. An attacker only needs a valid account on the GitLab instance (no user interaction) and network access to the service to exploit the flaw under the conditions described by the vendor. The weakness is classified as CWE-22 (Path Traversal).
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of GitLab GitLab are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 19.x | 18.8 – before 19.0.6 | 19.0.6 |
| 19.x | 19.1 – before 19.1.4 | 19.1.4 |
| 19.x | 19.2 – before 19.2.2 | 19.2.2 |
Is CVE-2026-10053 being exploited?
Public exploit code is available.
How to fix CVE-2026-10053
- Upgrade GitLab to one of the fixed releases: 19.0.6, 19.1.4, or 19.2.2 as appropriate for your branch.
- If you cannot upgrade immediately, restrict network access to the package registry and other GitLab services to trusted hosts only.
- Monitor GitLab logs and repositories for unusual uploads, deployments, or execution activity and investigate anomalous accounts.
- Apply vendor guidance and configuration hardening for the package registry from GitLab's security advisory.
Frequently asked questions
Is CVE-2026-10053 being actively exploited?
Public exploit code for CVE-2026-10053 is available.
Which GitLab versions are affected by CVE-2026-10053?
GitLab CE/EE versions 18.8 up to (but not including) 19.0.6, 19.1 up to 19.1.4, and 19.2 up to 19.2.2 are affected.
Is there a patch for CVE-2026-10053?
Yes; GitLab released fixes in versions 19.0.6, 19.1.4, and 19.2.2 for the respective branches.
Does CVE-2026-10053 require authentication?
Yes; the vulnerability requires an authenticated GitLab user account to exploit.
References
- nvd.nist.gov/vuln/detail/CVE-2026-10053
- cve.org/CVERecord?id=CVE-2026-10053
- gitlab.com/gitlab-org/gitlab/-/work_items/601596
- hackerone.com/reports/3754194
- All GitLab CVEs on CVE Radar
- CVEs published in September 2026