CVE-2026-13113: Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to merge code into a protected branch without the required approvals due to a race condition in approval rule processing.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.0.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13113?
The severity of CVE-2026-13113 is medium, rated at 6.5 on the CVSS scale.
How do I fix CVE-2026-13113?
To fix CVE-2026-13113, upgrade GitLab EE to version 19.0.5 or higher, 19.1.3 or higher, or 19.2.1 or higher.
What type of vulnerability is CVE-2026-13113?
CVE-2026-13113 is a Time-of-check Time-of-use (TOCTOU) race condition vulnerability.
Who is affected by CVE-2026-13113?
All versions of GitLab EE from 17.0 up to, but not including, 19.0.5, 19.1.3, and 19.2.1 are affected.
What impact does CVE-2026-13113 have?
CVE-2026-13113 could allow an authenticated user to merge code into a protected branch without the required approvals.