Executive brief
GitLab Enterprise Edition, a platform used by organizations to manage software development and source code, is affected by a vulnerability that allows users to disrupt the service. By uploading a specifically crafted file, a user can cause the system to become unresponsive or crash, leading to a denial of service. This impact prevents development teams from accessing their code and tools, potentially halting production workflows.
Technical details
A denial of service (DoS) vulnerability exists in GitLab Enterprise Edition (EE) due to improper validation during file uploads, specifically related to the deserialization of untrusted data (CWE-502). An authenticated attacker with network access can upload a specially crafted file that triggers resource exhaustion or application crashes. The issue affects a wide range of versions starting from 11.9. GitLab has released patches in versions 18.9.7, 18.10.6, and 18.11.3 to address the root cause by improving validation logic.
Affected products
- GitLab GitLab Enterprise Edition (EE) 11.9 to < 18.9.7, 18.10 to < 18.10.6, 18.11 to < 18.11.3
Timeline
- 2026-05-13: patched: GitLab released versions 18.9.7, 18.10.6, and 18.11.3
- 2026-05-14: disclosed: CVE-2026-1184 published