PatchSiren cyber security CVE debrief
CVE-2026-13113 GitLab CVE debrief
GitLab EE versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 are affected by a race condition in approval rule processing. This vulnerability could allow an authenticated user to merge code into a protected branch without the required approvals. The issue impacts GitLab EE deployments with specific configurations of protected branches and approval rules. Affected administrators and users should review and apply patches. Security teams should verify and enforce required approvals for protected branches and monitor for potential exposure. Asset owners and operators should inventory and update GitLab EE to versions 19.0.5, 19.1.3, or 19.2.1.
- Vendor
- GitLab
- Product
- Unknown
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-29
- Original CVE updated
- 2026-08-03
- Advisory published
- 2026-07-29
- Advisory updated
- 2026-08-03
Who should care
GitLab EE administrators and users with access to protected branches in affected versions should review and apply patches. Security teams and vulnerability management teams should verify and enforce required approvals for protected branches and monitor for potential exposure. Asset owners and operators should inventory and update GitLab EE to versions 19.0.5, 19.1.3, or 19.2.1.
Technical summary
A race condition in approval rule processing in GitLab EE versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 could allow an authenticated user to merge code into a protected branch without the required approvals. This issue affects GitLab EE deployments with specific configurations of protected branches and approval rules. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. The CVE record was published on 2026-07-29T20:17:00.550Z and has not been modified since then.
Defensive priority
Authenticated users with limited access could potentially merge code into protected branches without required approvals due to a race condition in approval rule processing in GitLab EE versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1.
Recommended defensive actions
- Review and apply patches from GitLab for affected versions
- Verify and enforce required approvals for protected branches
- Monitor for and restrict authenticated user access to sensitive branches
- Inventory and update GitLab EE to versions 19.0.5, 19.1.3, or 19.2.1
- Perform vulnerability scanning for exposed systems
- Implement compensating controls for exposed systems
- Track exceptions and retest remediated assets
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in GitLab EE. Vendor advisory and release notes are available for affected versions. Evidence limits suggest verifying GitLab EE versions 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1. Defenders should review approval rule processing and protected branch configurations.
Official resources
-
CVE-2026-13113 CVE record
CVE.org
-
CVE-2026-13113 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Release Notes, Vendor Advisory
-
Source reference
[email protected] - Broken Link
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T20:17:00.550Z and has not been modified since then.