Regular Expression Denial of Service in GitLab Community and Enterprise Edition
CVE-2026-1388
7.5HIGH
What is CVE-2026-1388?
A vulnerability in GitLab CE/EE allows an unauthenticated user to perform a regular expression denial of service attack. By sending specially crafted inputs to a specific merge request endpoint under certain conditions, this vulnerability could disrupt the service, rendering it inoperable. Remediation has been implemented in versions 18.7.5, 18.8.5, and 18.9.1, following the discovery of the issue. Detailed technical insights can be referenced in the associated GitLab issue and HackerOne report.
Affected Version(s)
GitLab 9.2 < 18.7.5
GitLab 18.8 < 18.8.5
GitLab 18.9 < 18.9.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [sim4n6](https://hackerone.com/sim4n6) for reporting this vulnerability through our HackerOne bug bounty program