Executive brief
GitLab has addressed a security vulnerability in its Community and Enterprise editions that could allow an unauthorized person to crash or slow down the service. By sending specially crafted requests to the system's API, an attacker can cause a denial-of-service condition, making the platform unavailable to legitimate users. This impact can disrupt software development workflows and internal operations until the service is restored.
Technical details
A denial-of-service (DoS) vulnerability exists in GitLab CE/EE versions 12.10 through 19.0.2 due to improper input validation within the API request parsing middleware. The flaw is categorized as CWE-770 (Allocation of Resources Without Limits or Throttling), where unauthenticated attackers can submit malicious API requests that exhaust system resources. This is a network-based attack requiring no prior authentication or user interaction. GitLab has released patches in versions 18.10.8, 18.11.5, and 19.0.2 to mitigate this issue.
Affected products
- GitLab GitLab Community Edition (CE) 12.10 to <18.10.8, 18.11 to <18.11.5, 19.0 to <19.0.2
- GitLab GitLab Enterprise Edition (EE) 12.10 to <18.10.8, 18.11 to <18.11.5, 19.0 to <19.0.2
Timeline
- 2026-06-10: patched: GitLab released versions 18.10.8, 18.11.5, and 19.0.2
- 2026-06-11: disclosed: Public advisory published by GitLab and NVD