PT-2026-97616 · Gitlab · Gitlab Ce/Ee

·

CVE-2026-89078

·

Published

2026-09-23

·

Updated

2026-09-29

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 19.2 through 19.2.6 GitLab CE/EE versions 19.3 through 19.3.2 GitLab CE/EE versions 19.4 through 19.4.0
Description An authenticated user can execute arbitrary code on the server due to a double free issue—a memory corruption flaw where the system attempts to free the same memory location twice—occurring when parsing a specially crafted regular expression in a CI/CD configuration. Approximately 1.3 million instances are identified globally.
Recommendations Update GitLab CE/EE version 19.2 to 19.2.7. Update GitLab CE/EE version 19.3 to 19.3.3. Update GitLab CE/EE version 19.4 to 19.4.1.

Exploit

Fix

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15214
BIT-GITLAB-2026-89078
CVE-2026-89078

Affected Products

Gitlab Ce/Ee