CVE-2026-93577

Published Sep 24, 2026

Last updated 12 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-93577 is an integer overflow vulnerability found in the regular expression compiler of GitLab CE/EE. This flaw could enable an authenticated user to execute arbitrary code on the GitLab server. The vulnerability is triggered when a specially crafted regular expression is compiled within a CI/CD configuration. Affected versions include all GitLab CE/EE versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1.

Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.
Source
cve@gitlab.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.9
Impact score
6
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cve@gitlab.com
CWE-190

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

14

  1. Toutes nos instances GitLab sont à jour en version 19.4.1 depuis hier soir à 22h. Il faut mettre à jour rapidement : cette nouvelle version corrige 2 CVE évaluées à 9,9 (CVE-2026-93577 et CVE-2026-84739). En savoir plus sur nos offres 👇 https://t.co/YFPUqGvB0E

    @bearstech

    24 Sept 2026

    1978 Impressions

    0 Retweets

    7 Likes

    2 Bookmarks

    0 Replies

    1 Quote

  2. 🚨 CRITICAL | GitLab Security Alert GitLab just shipped patches 19.4.1, 19.3.3 & 19.2.7 fixing two CVSS 9.9 Critical RCE flaws. 💥 CVE-2026-89078 — Double-free in regex parser 💥 CVE-2026-93577 — Integer overflow in regex compiler

    @exploitgrid

    24 Sept 2026

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. GitLab patches 11 vulnerabilities across CE and EE in versions 19.4.1, 19.3.3, and 19.2.7. Two Critical flaws (CVE-2026-89078 double-free and CVE-2026-93577 integer overflow) allow authenticated users to achieve arbitrary code execution via crafted regex in CI/CD components.

    @WorldCyberNewsX

    24 Sept 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Self-managed GitLab: two CVSS 9.9 RCEs landed yesterday. CVE-2026-89078 and CVE-2026-93577 let an authenticated user run code on the server via a crafted regex in CI/CD config. https://t.co/NTxojYX7ZM is patched. Your box is not.

    @Sunil_kumawat17

    24 Sept 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. GitLabに重大(Critical)な脆弱性が2件。CVE-2026-89078とCVE-2026-93577はCVSSスコア9.9で、それぞれ解放後メモリ使用と整数オーバーフローによる遠隔コード実行。ほか、クロスサイトスクリプティングのCVE-2026-84739と併せ

    @__kokumoto

    24 Sept 2026

    576 Impressions

    1 Retweet

    4 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 ALERT — CRITICAL GITLAB CI/CD RCE FLAWS DATE: September 23, 2026 CONFIRMED BY: GitLab PRODUCT: GitLab CE/EE — Self-Managed CVEs: CVE-2026-89078 — CVSS 9.9 CVE-2026-93577 — CVSS 9.9 IMPACT: Authenticated attackers may, under specific conditions, execute arbitrary c

    @Python_s_

    24 Sept 2026

    23 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 GitLab'da iki kritik RCE açığı için acil güvenlik güncellemesi yayınlandı! CVE-2026-89078 ve CVE-2026-93577, CI/CD yapılandırmalarında özel hazırlanmış regex'lerin işlenmesi sırasında oluşan double-free ve integer overflow hataları üzerinden, kimliği

    @ridvanyagli

    24 Sept 2026

    216 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 GITLAB CRITICAL PATCH: AUTH RCE VIA REGEX PARSER (CVE-2026-89078 / CVE-2026-93577) GitLab released Critical patch versions 19.4.1, 19.3.3, and 19.2.7 on September 23, 2026 for CE/EE. Lead Critical issues (both CVSS 9.9): * CVE-2026-89078 — authenticated remote code execu

    @DailyDarkWeb

    23 Sept 2026

    6368 Impressions

    8 Retweets

    33 Likes

    15 Bookmarks

    0 Replies

    1 Quote