PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-13113 GitLab CVE debrief

GitLab EE versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 are affected by a race condition in approval rule processing. This vulnerability could allow an authenticated user to merge code into a protected branch without the required approvals. The issue impacts GitLab EE deployments with specific configurations of protected branches and approval rules. Affected administrators and users should review and apply patches. Security teams should verify and enforce required approvals for protected branches and monitor for potential exposure. Asset owners and operators should inventory and update GitLab EE to versions 19.0.5, 19.1.3, or 19.2.1.

Vendor
GitLab
Product
Unknown
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-29
Original CVE updated
2026-08-03
Advisory published
2026-07-29
Advisory updated
2026-08-03

Who should care

GitLab EE administrators and users with access to protected branches in affected versions should review and apply patches. Security teams and vulnerability management teams should verify and enforce required approvals for protected branches and monitor for potential exposure. Asset owners and operators should inventory and update GitLab EE to versions 19.0.5, 19.1.3, or 19.2.1.

Technical summary

A race condition in approval rule processing in GitLab EE versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 could allow an authenticated user to merge code into a protected branch without the required approvals. This issue affects GitLab EE deployments with specific configurations of protected branches and approval rules. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. The CVE record was published on 2026-07-29T20:17:00.550Z and has not been modified since then.

Defensive priority

Authenticated users with limited access could potentially merge code into protected branches without required approvals due to a race condition in approval rule processing in GitLab EE versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1.

Recommended defensive actions

  • Review and apply patches from GitLab for affected versions
  • Verify and enforce required approvals for protected branches
  • Monitor for and restrict authenticated user access to sensitive branches
  • Inventory and update GitLab EE to versions 19.0.5, 19.1.3, or 19.2.1
  • Perform vulnerability scanning for exposed systems
  • Implement compensating controls for exposed systems
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in GitLab EE. Vendor advisory and release notes are available for affected versions. Evidence limits suggest verifying GitLab EE versions 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1. Defenders should review approval rule processing and protected branch configurations.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T20:17:00.550Z and has not been modified since then.