CVE-2026-89078

Published Sep 24, 2026

Last updated 7 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-89078 is identified as a double free vulnerability affecting the regular expression parser in GitLab Community Edition (CE) and Enterprise Edition (EE). This flaw could enable an authenticated user to execute arbitrary code on the GitLab server. The vulnerability is triggered when a specially crafted regular expression is parsed within a CI/CD configuration. GitLab has released remediations for this issue, impacting versions 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1.

Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration.
Source
cve@gitlab.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.9
Impact score
6
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Severity
CRITICAL

Weaknesses

cve@gitlab.com
CWE-415

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

14

  1. ⚠️ Vulnerabilidades en GitLab CE/EE ❗ CVE-2026-93577 ❗ CVE-2026-89078 ➡️ Más info: https://t.co/Bmlnd0SYtC https://t.co/5Z4cxOyWce

    @CERTpy

    24 Sept 2026

    123 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Warning: Critical Remote Code Execution Vulnerabilities in #GitLab. #CVE-2026-89078 #CVE-2026-93577 CVSS: 9.9. Flaws in the regex engine allow full server takeover via #RCE! #Patch #Patch #Patch More info in our advisory: https://t.co/OqMLS8HM12

    @CCBalert

    24 Sept 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CRITICAL | GitLab Security Alert GitLab just shipped patches 19.4.1, 19.3.3 & 19.2.7 fixing two CVSS 9.9 Critical RCE flaws. 💥 CVE-2026-89078 — Double-free in regex parser 💥 CVE-2026-93577 — Integer overflow in regex compiler

    @exploitgrid

    24 Sept 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. GitLab patches 11 vulnerabilities across CE and EE in versions 19.4.1, 19.3.3, and 19.2.7. Two Critical flaws (CVE-2026-89078 double-free and CVE-2026-93577 integer overflow) allow authenticated users to achieve arbitrary code execution via crafted regex in CI/CD components.

    @WorldCyberNewsX

    24 Sept 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Self-managed GitLab: two CVSS 9.9 RCEs landed yesterday. CVE-2026-89078 and CVE-2026-93577 let an authenticated user run code on the server via a crafted regex in CI/CD config. https://t.co/NTxojYX7ZM is patched. Your box is not.

    @Sunil_kumawat17

    24 Sept 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. GitLabに重大(Critical)な脆弱性が2件。CVE-2026-89078とCVE-2026-93577はCVSSスコア9.9で、それぞれ解放後メモリ使用と整数オーバーフローによる遠隔コード実行。ほか、クロスサイトスクリプティングのCVE-2026-84739と併せ

    @__kokumoto

    24 Sept 2026

    640 Impressions

    1 Retweet

    4 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 ALERT — CRITICAL GITLAB CI/CD RCE FLAWS DATE: September 23, 2026 CONFIRMED BY: GitLab PRODUCT: GitLab CE/EE — Self-Managed CVEs: CVE-2026-89078 — CVSS 9.9 CVE-2026-93577 — CVSS 9.9 IMPACT: Authenticated attackers may, under specific conditions, execute arbitrary c

    @Python_s_

    24 Sept 2026

    23 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 GitLab'da iki kritik RCE açığı için acil güvenlik güncellemesi yayınlandı! CVE-2026-89078 ve CVE-2026-93577, CI/CD yapılandırmalarında özel hazırlanmış regex'lerin işlenmesi sırasında oluşan double-free ve integer overflow hataları üzerinden, kimliği

    @ridvanyagli

    24 Sept 2026

    216 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 GITLAB CRITICAL PATCH: AUTH RCE VIA REGEX PARSER (CVE-2026-89078 / CVE-2026-93577) GitLab released Critical patch versions 19.4.1, 19.3.3, and 19.2.7 on September 23, 2026 for CE/EE. Lead Critical issues (both CVSS 9.9): * CVE-2026-89078 — authenticated remote code execu

    @DailyDarkWeb

    23 Sept 2026

    7779 Impressions

    9 Retweets

    45 Likes

    24 Bookmarks

    0 Replies

    1 Quote