Junglewise Threat Intelligence

CVE-2026-15975: GitLab CE/EE denial of service in merge request discussions

CVE-2026-15975 · Severity: high · CVSS 7.5 · Published 2026-07-29

Executive brief

GitLab, a platform used by software teams to manage code and collaborate on projects, has addressed a security flaw that could allow an unauthorized user to crash or slow down the service. By sending specifically crafted requests to the merge request discussion feature, an attacker could overwhelm the system's resources. This could lead to a denial of service, preventing legitimate users from accessing their code and disrupting development operations.

Technical details

A denial of service vulnerability exists in GitLab CE/EE due to insufficient resource throttling (CWE-770) within the merge request discussion processing component. An unauthenticated remote attacker can exploit this by sending specially crafted requests that consume excessive system resources. Successful exploitation allows the attacker to cause a denial of service condition, impacting the availability of the GitLab instance. The issue affects versions 11.8 through 19.0.5, 19.1 through 19.1.3, and 19.2 through 19.2.1. Patches have been released in versions 19.0.5, 19.1.3, and 19.2.1.

Affected products

  • GitLab GitLab Community Edition (CE) 11.8 to 19.0.5, 19.1 to 19.1.3, 19.2 to 19.2.1
  • GitLab GitLab Enterprise Edition (EE) 11.8 to 19.0.5, 19.1 to 19.1.3, 19.2 to 19.2.1

Timeline

  • 2026-07-29: patched: GitLab released versions 19.2.1, 19.1.3, and 19.0.5 to address the issue.
  • 2026-07-29: advisory: NVD and GitLab published the vulnerability details.

References

Related threats