MEDIUM
CVE-2026-1402
CVSS
6.5
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to cause denial of service due to insufficient validation.
Summary dbcve.org
GitLab CE/EE versions 17.1 through 18.10.6, 18.11.3, and 19.0.0 contain an insufficient validation flaw that allows authenticated users to trigger a denial of service condition. The vulnerability requires user authentication but can be exploited to cause service disruption.
Mitigation
Upgrade GitLab to version 18.10.7, 18.11.4, 19.0.1 or later. For environments unable to upgrade immediately, restrict authenticated access and monitor for unusual activity patterns.
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
0.47%
Probability of exploitation in next 30 days
39.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.