Denial of Service Vulnerability in GitLab Products by GitLab
CVE-2026-1659
7.5HIGH
What is CVE-2026-1659?
A vulnerability exists in GitLab CE/EE that affects various versions, potentially allowing unauthenticated users to execute denial of service attacks. This can occur when specially crafted requests are sent due to a lack of proper input validation mechanisms. As a result, the service may become unavailable, affecting users and organizations relying on GitLab for their workflow.
Affected Version(s)
GitLab 9.0 < 18.9.7
GitLab 18.10 < 18.10.6
GitLab 18.11 < 18.11.3
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [a92847865](https://hackerone.com/a92847865) for reporting this vulnerability through our HackerOne bug bounty program