Junglewise Threat Intelligence

CVE-2026-1659: GitLab CE/EE denial of service via insufficient input validation

CVE-2026-1659 · Severity: high · CVSS 7.5 · Published 2026-05-14

Technologies: GitLab Enterprise Edition (EE), GitLab Community Edition. Vendors: GitLab.

Executive brief

GitLab has addressed a security vulnerability in its Community and Enterprise editions that could allow an attacker to crash or slow down the service. By sending specially crafted network requests, an unauthenticated user could trigger a denial-of-service condition, making the platform unavailable to legitimate developers and automated pipelines. This impact can disrupt software development workflows and delay production deployments until the service is restored.

Technical details

A denial of service vulnerability exists in GitLab CE/EE versions 9.0 through 18.11.3 due to insufficient input validation (CWE-770). An unauthenticated remote attacker can exploit this by sending specially crafted requests that lead to resource exhaustion or service instability. The vulnerability is categorized as 'Allocation of Resources Without Limits or Throttling,' suggesting that the crafted input triggers excessive memory or CPU consumption. GitLab has released patches in versions 18.9.7, 18.10.6, and 18.11.3 to remediate the issue.

Affected products

  • GitLab GitLab Community Edition (CE) 9.0 to <18.9.7, 18.10 to <18.10.6, 18.11 to <18.11.3
  • GitLab GitLab Enterprise Edition (EE) 9.0 to <18.9.7, 18.10 to <18.10.6, 18.11 to <18.11.3

Timeline

  • 2026-05-13: patched: GitLab released versions 18.9.7, 18.10.6, and 18.11.3
  • 2026-05-14: disclosed: CVE-2026-1659 published to the NVD

References

Related threats