CVE-2026-92628

Summary

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race condition, the MCP search tool's shared state handling could have caused search results to be returned under an incorrect user context.

Affected Software

VendorProductVersion RangeStatus
GitLabGitLab18.6 < 19.2.7affected
GitLabGitLab19.3 < 19.3.3affected
GitLabGitLab19.4 < 19.4.1affected

Weaknesses

  • CWE-362: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

References