Regular Expression Denial of Service in GitLab Community and Enterprise Edition
CVE-2026-1388
What is CVE-2026-1388?
A vulnerability in GitLab CE/EE allows an unauthenticated user to perform a regular expression denial of service attack. By sending specially crafted inputs to a specific merge request endpoint under certain conditions, this vulnerability could disrupt the service, rendering it inoperable. Remediation has been implemented in versions 18.7.5, 18.8.5, and 18.9.1, following the discovery of the issue. Detailed technical insights can be referenced in the associated GitLab issue and HackerOne report.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GitLab 9.2 < 18.7.5
GitLab 18.8 < 18.8.5
GitLab 18.9 < 18.9.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved