Medium severity6.5NVD Advisory· Published Jul 29, 2026· Updated Aug 3, 2026
CVE-2026-13113
CVE-2026-13113
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to merge code into a protected branch without the required approvals due to a race condition in approval rule processing.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*+ 1 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=17.0.0,<19.0.5
- cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*
- Range: <19.0.5, 19.1 <19.1.3, 19.2 <19.2.1
Patches
Vulnerability mechanics
References
1- docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/nvdRelease NotesVendor Advisory
News mentions
2- GitLab Fixes 13 Security Flaws That Can Leak Data, Alter Pipelines, and Crash ServersCyber Security News · Jul 30, 2026
- GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5GitLab Security Releases · Jul 29, 2026