MEDIUM

CVE-2026-1402

Gitlab GitLab 2026-05-27 CVSS v3.1
CVSS
6.5

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to cause denial of service due to insufficient validation.

Summary dbcve.org

GitLab CE/EE versions 17.1 through 18.10.6, 18.11.3, and 19.0.0 contain an insufficient validation flaw that allows authenticated users to trigger a denial of service condition. The vulnerability requires user authentication but can be exploited to cause service disruption.

Mitigation

Upgrade GitLab to version 18.10.7, 18.11.4, 19.0.1 or later. For environments unable to upgrade immediately, restrict authenticated access and monitor for unusual activity patterns.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

0.47%
Probability of exploitation in next 30 days
39.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE