Executive brief
GitLab is a platform used by software teams to manage code and automate software delivery. A vulnerability in the CI/CD Catalog page could allow a logged-in user to trigger a denial of service, potentially making that specific feature unavailable to other users. GitLab has released security updates to address this issue across several versions.
Technical details
A denial of service (DoS) vulnerability exists in GitLab Community and Enterprise Editions within the CI/CD Catalog component. The flaw is rooted in improper sanitization of input, which can be exploited by an authenticated user to disrupt the availability of the CI/CD Catalog page. The vulnerability is tracked as CWE-1021 (Improper Restriction of Rendered UI Layers or Frames) by the vendor, though the primary impact is described as a service disruption. The issue affects multiple major version branches including 17.x, 18.x, and 19.x. Patches have been released in versions 18.10.8, 18.11.5, and 19.0.2.
Affected products
- GitLab GitLab CE/EE 17.0 to < 18.10.8, 18.11 to < 18.11.5, 19.0 to < 19.0.2
Timeline
- 2026-06-10: patched: GitLab released versions 18.10.8, 18.11.5, and 19.0.2
- 2026-06-11: disclosed: NVD publication date