VDB
GCVE-110-NCSC-2026-103
GCVE-110-NCSC-2026-103
Advisory PublishedCVSS 6.5/10
GitLab addressed a denial of service vulnerability affecting versions 16.10 to before 18.8.7, 18.9 to before 18.9.3, and 18.10 to before 18.10.1, which allowed authenticated users to cause excessive resource consumption via specific webhook configurations.
Weaknesses (CWE)
CWE-1284Improper Validation of Specified Quantity in InputCWE-770Allocation of Resources Without Limits or ThrottlingCWE-862Missing AuthorizationCWE-306Missing Authentication for Critical FunctionCWE-863Incorrect AuthorizationCWE-288Authentication Bypass Using an Alternate Path or ChannelCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)CWE-352Cross-Site Request Forgery (CSRF)CWE-407Inefficient Algorithmic Complexity
Risk Scores
CVSS 3.1
6.5/10
Medium · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GitLab | vers:unknown/* | — | — |
| Open Source | vers:unknown/* | — | — |
Browse GCVE Records
74,581 records in the GCVE database · Updated July 24, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.