Executive brief
GitLab, a platform used by organizations to manage and host software code, has addressed a security flaw that could allow a registered user to crash or slow down the service. By exploiting insufficient data validation, an attacker can trigger a denial-of-service condition, potentially disrupting software development workflows and preventing teams from accessing their projects. This issue affects both the Community and Enterprise editions of GitLab.
Technical details
A denial-of-service (DoS) vulnerability exists in GitLab CE/EE versions 17.1 through 19.0.1 due to insufficient validation of user-supplied data, specifically categorized as CWE-770 (Allocation of Resources Without Limits or Throttling). An authenticated attacker with network access can exploit this flaw to cause resource exhaustion, leading to service unavailability. The vulnerability requires low privileges to execute and does not require user interaction. GitLab has released patches in versions 18.10.7, 18.11.4, and 19.0.1 to remediate the issue.
Affected products
- GitLab GitLab Community Edition (CE) 17.1 to <18.10.7, 18.11 to <18.11.4, 19.0 to <19.0.1
- GitLab GitLab Enterprise Edition (EE) 17.1 to <18.10.7, 18.11 to <18.11.4, 19.0 to <19.0.1
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory
- 2026-05-27: patched