Package
gitlab-rails-ce-19.0
Component
devise
Latest update
6.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
GitLab bundles devise 4.9.4 via its Gemfile.lock; the fix for CVE-2026-40295 (GHSA-jp94-3292-c3xv) is in devise 5.0.4, a major-version upgrade GitLab has not adopted. Per GitLab's dependency policy, dependencies are not upgraded manually ahead of upstream, and major bumps risk runtime breakage invisible at build time. Deferring to upstream (GitLab) to adopt devise >= 5.0.4. See: https://docs.gitlab.com/ee/development/dependencies.html
Status