{
  "id": 11219654,
  "title": "What Discloses From GitLab EE CVE-2026-87719: Advanced Search Configuration and Credentials",
  "url": "https://urgent.news/2026/10/01/what-discloses-from-gitlab-ee-cve-2026-87719-advanced-search",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-01T15:20:21.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/stark_zhuang_df5076f35c68/what-discloses-from-gitlab-ee-cve-2026-87719-advanced-search-configuration-and-credentials-56ad"
  },
  "original_language": "en",
  "account": "GitLab Enterprise Edition (EE) has been hit by a critical vulnerability, CVE-2026-87719, which allows attackers with the proper access to obtain Advanced Search instance configurations and sensitive credentials. This issue, classified as CWE-502, stems from insecure deserialization when GitLab EE builds a server-side object from a client-supplied argument in a GraphQL subscription. The vulnerability can be exploited without user interaction, making it particularly dangerous. GitLab released patches for EE versions 18.11.12, 19.0.9, 19.1.8, 19.2.6, and 19.3.2, which address the flaw. The risk is widespread, with ZoomEye estimating 1,326,958 instances of the affected software. Administrators are advised to upgrade to the latest versions, rotate credentials, and review access controls.",
  "summary": "What Discloses From GitLab EE CVE-2026-87719: Advanced Search Configuration and Credentials Overview Advanced Search pushes indexed data to a backing search cluster, and CVE-2026-87719 is a critical path to its configuration. The vulnerability is CWE-502, insecure deserialization, in GitLab Enterprise Edition, and it carries a CVSS 3.1 base score of 9.9. GitLab fixed it on 10 September 2026 in…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}