CVE-2026-1102
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending repeated malformed SSH authentication requests.
Summary dbcve.org
An unauthenticated attacker can cause denial of service by sending repeated malformed SSH authentication requests to GitLab CE/EE. This exploits a vulnerability in GitLab's SSH authentication handling mechanism, allowing resource exhaustion without authentication.
Mitigation
Upgrade GitLab to version 18.6.4, 18.7.2, 18.8.2 or later to remediate the vulnerability. Alternatively, consider rate-limiting or restricting SSH access at the network perimeter until the upgrade can be performed.