CVE-2026-92628
📛 CVE Title
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitLab
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race condition, the MCP search tool's shared state handling could have caused search results to be returned under an incorrect user context.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- GitLab
- CVSS severity
- LOW
- CVSS score
- 3.1 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N- Effective score
- 3.1 / 10 LOW source: CNA overview
- CWE(s)
-
CWE-362 - Reserved
- 2026-09-16
- Published
- 2026-09-23 23:04 UTC
- Last updated
- 2026-09-23 23:04 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/92xxx/CVE-2026-92628.json
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-24 00:17:22 UTC
- NVD last modified
- 2026-09-24 00:17:22 UTC
- NVD CVSS v3.1
- 3.1 / 10 LOW source: cve@gitlab.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N- Exploitability subscore
- 1.6 / 10
- Impact subscore
- 1.4 / 10
NVD / KEV / EPSS data refreshed 2026-09-24 04:29 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-85731 - Assigner
- GitLab
- Published
- Sep 23, 2026, 11:04:50 PM
- Updated
- Sep 23, 2026, 11:04:50 PM
- EUVD base score (CVSS 3.1)
-
3.1 / 10
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N - EUVD-reported EPSS
- 0.0000
- Vendors
- GitLab
- Products
-
GitLab (18.6 <19.2.7)GitLab (19.3 <19.3.3)GitLab (19.4 <19.4.1)
- Aliases
-
GHSA-vp7f-562j-4qgr
ENISA description: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race condition, the MCP search tool's shared state handling could have caused search results to be returned under an incorrect user context.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GitLab | GitLab |
18.6 (affected),
19.3 (affected),
19.4 (affected)
|
— |
Vendor references (2)
References embedded in the original CVE record by the assigning CNA.
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (2)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-92628.json.
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"product": "GitLab",
"repo": "git://git@gitlab.com:gitlab-org/gitlab.git",
"vendor": "GitLab",
"versions": [
{
"lessThan": "19.2.7",
"status": "affected",
"version": "18.6",
"versionType": "semver"
},
{
"lessThan": "19.3.3",
"status": "affected",
"version": "19.3",
"versionType": "semver"
},
{
"lessThan": "19.4.1",
"status": "affected",
"version": "19.4",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "This vulnerability has been discovered internally by GitLab team member Chris Bonk"
}
],
"descriptions": [
{
"lang": "en",
"value": "GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race condition, the MCP search tool's shared state handling could have caused search results to be returned under an incorrect user context."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 3.1,
"baseSeverity": "LOW",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-362",
"description": "CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T23:04:50.132Z",
"orgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
"shortName": "GitLab"
},
"references": [
{
"url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/621933"
},
{
"url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/"
}
],
"solutions": [
{
"lang": "en",
"value": "Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above."
}
],
"title": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitLab"
}
},
"cveMetadata": {
"assignerOrgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
"assignerShortName": "GitLab",
"cveId": "CVE-2026-92628",
"datePublished": "2026-09-23T23:04:50.132Z",
"dateReserved": "2026-09-16T15:35:11.125Z",
"dateUpdated": "2026-09-23T23:04:50.132Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}