GitLab 19.4.1 closes two CVSS 9.9 RCEs in the CI/CD regex parser
On September 23, 2026, GitLab released a critical patch for 19.4.1, 19.3.3, and 19.2.7, closing two remote code execution flaws at CVSS 9.9 in the pipeline’s regular-expression parser, triggerable by a forged .gitlab-ci.yml file. Any authenticated user who can edit a CI/CD configuration becomes a vector: patch self-managed instances immediately.