VDB

GCVE-110-NCSC-2026-103

GCVE-110-NCSC-2026-103
Advisory PublishedCVSS 6.5/10
Vulnetix · Advisory published March 26, 2026
GitLab addressed a denial of service vulnerability affecting versions 16.10 to before 18.8.7, 18.9 to before 18.9.3, and 18.10 to before 18.10.1, which allowed authenticated users to cause excessive resource consumption via specific webhook configurations.

Weaknesses (CWE)

CWE-1284Improper Validation of Specified Quantity in InputCWE-770Allocation of Resources Without Limits or ThrottlingCWE-862Missing AuthorizationCWE-306Missing Authentication for Critical FunctionCWE-863Incorrect AuthorizationCWE-288Authentication Bypass Using an Alternate Path or ChannelCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)CWE-352Cross-Site Request Forgery (CSRF)CWE-407Inefficient Algorithmic Complexity

Risk Scores

CVSS 3.1
6.5/10
Medium · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersionsPlatforms
GitLabvers:unknown/*
Open Sourcevers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,581 records in the GCVE database · Updated July 24, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›