Junglewise Threat Intelligence

CVE-2026-1184: GitLab EE denial of service via improper file validation

CVE-2026-1184 · Severity: medium · CVSS 6.5 · Published 2026-05-14

Technologies: GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab Enterprise Edition, a platform used by organizations to manage software development and source code, is affected by a vulnerability that allows users to disrupt the service. By uploading a specifically crafted file, a user can cause the system to become unresponsive or crash, leading to a denial of service. This impact prevents development teams from accessing their code and tools, potentially halting production workflows.

Technical details

A denial of service (DoS) vulnerability exists in GitLab Enterprise Edition (EE) due to improper validation during file uploads, specifically related to the deserialization of untrusted data (CWE-502). An authenticated attacker with network access can upload a specially crafted file that triggers resource exhaustion or application crashes. The issue affects a wide range of versions starting from 11.9. GitLab has released patches in versions 18.9.7, 18.10.6, and 18.11.3 to address the root cause by improving validation logic.

Affected products

  • GitLab GitLab Enterprise Edition (EE) 11.9 to < 18.9.7, 18.10 to < 18.10.6, 18.11 to < 18.11.3

Timeline

  • 2026-05-13: patched: GitLab released versions 18.9.7, 18.10.6, and 18.11.3
  • 2026-05-14: disclosed: CVE-2026-1184 published

References

Related threats