CVE-2026-15387: Acceptance of Extraneous Untrusted Data With Trusted Data in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have influenced the execution environment of Pipeline Execution Policy enforcement jobs, due to improper handling of job dependencies.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.1.7 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.2.5 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.3.1
Event History
Frequently Asked Questions
Which GitLab EE deployments are affected?
Affected versions are GitLab EE 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1. Other versions are not identified as affected by the provided information.
What access does an attacker need?
An attacker must be authenticated and have Developer-role permissions. Exploitation also requires the conditions in which Pipeline Execution Policy enforcement jobs are used and the improper handling of job dependencies can influence their execution environment.
What is the security impact?
A Developer-role user could influence the execution environment of Pipeline Execution Policy enforcement jobs. The reported impact is integrity-only; no confidentiality or availability impact is specified.
What version should be used to remediate the issue?
Upgrade GitLab EE to 19.1.7, 19.2.5, or 19.3.1 or later within the applicable release line.