AI description
CVE-2026-93577 is an integer overflow vulnerability found in the regular expression compiler of GitLab CE/EE. This flaw could enable an authenticated user to execute arbitrary code on the GitLab server. The vulnerability is triggered when a specially crafted regular expression is compiled within a CI/CD configuration. Affected versions include all GitLab CE/EE versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1.
- Description
- GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.
- Source
- cve@gitlab.com
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 9.9
- Impact score
- 6
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- cve@gitlab.com
- CWE-190
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
14
Toutes nos instances GitLab sont à jour en version 19.4.1 depuis hier soir à 22h. Il faut mettre à jour rapidement : cette nouvelle version corrige 2 CVE évaluées à 9,9 (CVE-2026-93577 et CVE-2026-84739). En savoir plus sur nos offres 👇 https://t.co/YFPUqGvB0E
@bearstech
24 Sept 2026
1978 Impressions
0 Retweets
7 Likes
2 Bookmarks
0 Replies
1 Quote
🚨 CRITICAL | GitLab Security Alert GitLab just shipped patches 19.4.1, 19.3.3 & 19.2.7 fixing two CVSS 9.9 Critical RCE flaws. 💥 CVE-2026-89078 — Double-free in regex parser 💥 CVE-2026-93577 — Integer overflow in regex compiler
@exploitgrid
24 Sept 2026
16 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
GitLab patches 11 vulnerabilities across CE and EE in versions 19.4.1, 19.3.3, and 19.2.7. Two Critical flaws (CVE-2026-89078 double-free and CVE-2026-93577 integer overflow) allow authenticated users to achieve arbitrary code execution via crafted regex in CI/CD components.
@WorldCyberNewsX
24 Sept 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Self-managed GitLab: two CVSS 9.9 RCEs landed yesterday. CVE-2026-89078 and CVE-2026-93577 let an authenticated user run code on the server via a crafted regex in CI/CD config. https://t.co/NTxojYX7ZM is patched. Your box is not.
@Sunil_kumawat17
24 Sept 2026
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
GitLabに重大(Critical)な脆弱性が2件。CVE-2026-89078とCVE-2026-93577はCVSSスコア9.9で、それぞれ解放後メモリ使用と整数オーバーフローによる遠隔コード実行。ほか、クロスサイトスクリプティングのCVE-2026-84739と併せ
@__kokumoto
24 Sept 2026
576 Impressions
1 Retweet
4 Likes
2 Bookmarks
0 Replies
0 Quotes
🚨 ALERT — CRITICAL GITLAB CI/CD RCE FLAWS DATE: September 23, 2026 CONFIRMED BY: GitLab PRODUCT: GitLab CE/EE — Self-Managed CVEs: CVE-2026-89078 — CVSS 9.9 CVE-2026-93577 — CVSS 9.9 IMPACT: Authenticated attackers may, under specific conditions, execute arbitrary c
@Python_s_
24 Sept 2026
23 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 GitLab'da iki kritik RCE açığı için acil güvenlik güncellemesi yayınlandı! CVE-2026-89078 ve CVE-2026-93577, CI/CD yapılandırmalarında özel hazırlanmış regex'lerin işlenmesi sırasında oluşan double-free ve integer overflow hataları üzerinden, kimliği
@ridvanyagli
24 Sept 2026
216 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 GITLAB CRITICAL PATCH: AUTH RCE VIA REGEX PARSER (CVE-2026-89078 / CVE-2026-93577) GitLab released Critical patch versions 19.4.1, 19.3.3, and 19.2.7 on September 23, 2026 for CE/EE. Lead Critical issues (both CVSS 9.9): * CVE-2026-89078 — authenticated remote code execu
@DailyDarkWeb
23 Sept 2026
6368 Impressions
8 Retweets
33 Likes
15 Bookmarks
0 Replies
1 Quote