CVE-2026-77801

Published Aug 26, 2026

Last updated 4 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-77801 is a denial-of-service vulnerability identified in GitLab Community Edition (CE) and Enterprise Edition (EE). The flaw stems from a lack of object count limits, which allows an authenticated user to disrupt background job processing. This can lead to resource exhaustion, thereby degrading or halting asynchronous operations across the GitLab instance. The vulnerability affects GitLab CE/EE versions 12.8 through 19.1.6, 19.2 through 19.2.4, and version 19.3.0. GitLab has since released patched versions (19.1.7, 19.2.5, and 19.3.1) to address this issue.

Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, could have allowed an authenticated user to cause a denial of service affecting background job processing, due to missing object count limits.
Source
cve@gitlab.com
NVD status
Analyzed
Products
gitlab

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity
MEDIUM

Weaknesses

cve@gitlab.com
CWE-770

Social media

Hype score
Not currently trending

Configurations