What is CVE-2026-13113?
This vulnerability affects GitLab EE versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1, potentially allowing an authenticated user to merge code into a protected branch without required approvals under certain conditions due to a race condition. It is recommended to update GitLab EE to versions 19.0.5, 19.1.3, or 19.2.1 to remediate the issue.
Azərbaycanca: GitLab EE-nin 17.0-dən 19.0.5, 19.1-dən 19.1.3 və 19.2-dən 19.2.1-ə qədər versiyalarını təsir edən bu boşluq, autentifikasiya olunmuş istifadəçiyə müəyyən şərtlər altında race condition səbəbilə qorunan branch-ə tələb olunan təsdiqlər olmadan kod birləşdirməyə imkan verə bilərdi. Təhlükəsizlik üçün GitLab EE-ni 19.0.5, 19.1.3 və ya 19.2.1 versiyalarına yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: GitLab
FAQ2
What impact could an attacker have by exploiting CVE-2026-13113?
This vulnerability could potentially allow an authenticated user to merge code into a protected branch without required approvals under certain conditions due to a race condition.
Which GitLab EE versions are affected by CVE-2026-13113?
GitLab EE versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.