Executive brief
GitLab, a widely-used platform for version control and collaboration, contains a vulnerability in its namespace transfer feature that could allow an authenticated attacker to prevent other users from modifying group settings. An attacker with valid credentials could exploit improper validation of group URL slugs during namespace transfers to lock another user out of administrative changes, disrupting team collaboration and project management.
Technical details
CVE-2026-8030 is an improper input validation vulnerability in GitLab's namespace transfer mechanism that stems from inadequate validation of group URL slugs. An authenticated attacker can manipulate group namespace transfers to create a collision or conflict that prevents the legitimate group owner from modifying group settings. The attack requires valid authentication and knowledge of the target group; no network-specific preconditions beyond standard GitLab access are needed. The impact is denial of service to group administrative functions rather than data exfiltration. Patches are available in versions 19.1.8, 19.2.6, and 19.3.2.
Affected products
- GitLab GitLab Community Edition 13.0 to 19.1.7, 19.2.0 to 19.2.5, 19.3.0 to 19.3.1
- GitLab GitLab Enterprise Edition 13.0 to 19.1.7, 19.2.0 to 19.2.5, 19.3.0 to 19.3.1
Timeline
- 2026-09-16: disclosed: CVE-2026-8030 published
- 2026-09-10: patched: Patch released in GitLab CE/EE versions 19.1.8, 19.2.6, 19.3.2