
Stanislav@stanislavdevops
GitLab 19.4.1, 19.3.3 and 19.2.7 fix two 9.9 RCEs. A signed-in user runs code on the server with a crafted regex in CI config. Signed-in is only as strict as your sign-up policy. Open registration means anyone. And CVE-2026-4523 is rated low but exposes CI job traces with secrets to users who aren't signed in. https://privatedevops.com/news/gitlab-ci-regex-rce-patch
0000020
4 followersView on X
