VDB
GCVE-110-NCSC-2026-93
GCVE-110-NCSC-2026-93
Advisory PublishedCVSS 5.0/10
GitLab addressed a denial of service vulnerability caused by improper input validation in the protected branches API affecting versions 16.11 to before 18.7.6, 18.8 to before 18.8.6, and 18.9 to before 18.9.2.
Weaknesses (CWE)
CWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')CWE-863Incorrect AuthorizationCWE-770Allocation of Resources Without Limits or ThrottlingCWE-116Improper Encoding or Escaping of OutputCWE-862Missing AuthorizationCWE-1284Improper Validation of Specified Quantity in InputCWE-288Authentication Bypass Using an Alternate Path or ChannelCWE-674Uncontrolled RecursionCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-212Improper Removal of Sensitive Information Before Storage or TransferCWE-706Use of Incorrectly-Resolved Name or Reference
Risk Scores
CVSS 3.1
5.0/10
Medium · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GitLab | vers:unknown/* | — | — |
Browse GCVE Records
74,366 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.