Executive brief
GitLab has fixed a security vulnerability in its Enterprise Edition that could allow a logged-in user to crash or significantly slow down the GitLab service. By sending specifically crafted requests to the software's Bill of Materials (SBOM) interface, an attacker could disrupt operations and prevent other employees from accessing the platform. This issue affects self-managed installations, while GitLab.com and Dedicated customers have already been protected.
Technical details
A denial of service (DoS) vulnerability exists in GitLab Enterprise Edition (EE) due to improper validation of specified quantities in GraphQL queries (CWE-1284). Specifically, the GraphQL SBOM API fails to correctly validate input, allowing an authenticated attacker to submit resource-intensive queries that exhaust system resources. This can lead to a complete denial of service for the GitLab instance. The vulnerability affects versions 18.2 through 18.10.2 and has been remediated in versions 18.8.9, 18.9.5, and 18.10.3. Exploitation requires network access and valid user authentication.
Affected products
- GitLab GitLab Enterprise Edition (EE) 18.2 to 18.8.8, 18.9 to 18.9.4, 18.10 to 18.10.2
Timeline
- 2026-04-08: patched: GitLab released versions 18.10.3, 18.9.5, and 18.8.9
- 2026-04-08: disclosed: Initial advisory publication