PT-2026-97622 · Gitlab · Gitlab Ce/Ee

·

CVE-2026-93577

·

Published

2026-09-23

·

Updated

2026-09-29

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 19.2 through 19.2.6 GitLab CE/EE versions 19.3 through 19.3.2 GitLab CE/EE versions 19.4 through 19.4.0
Description An integer overflow occurs when compiling a specially crafted regular expression within a CI/CD configuration. This issue allows an authenticated user to execute arbitrary code on the server.
Recommendations Update GitLab CE/EE version 19.2 to 19.2.7. Update GitLab CE/EE version 19.3 to 19.3.3. Update GitLab CE/EE version 19.4 to 19.4.1.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15215
BIT-GITLAB-2026-93577
CVE-2026-93577

Affected Products

Gitlab Ce/Ee