VDB

GCVE-110-NCSC-2026-93

GCVE-110-NCSC-2026-93
Advisory PublishedCVSS 5.0/10
Vulnetix · Advisory published March 12, 2026
GitLab addressed a denial of service vulnerability caused by improper input validation in the protected branches API affecting versions 16.11 to before 18.7.6, 18.8 to before 18.8.6, and 18.9 to before 18.9.2.

Weaknesses (CWE)

CWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')CWE-863Incorrect AuthorizationCWE-770Allocation of Resources Without Limits or ThrottlingCWE-116Improper Encoding or Escaping of OutputCWE-862Missing AuthorizationCWE-1284Improper Validation of Specified Quantity in InputCWE-288Authentication Bypass Using an Alternate Path or ChannelCWE-674Uncontrolled RecursionCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-212Improper Removal of Sensitive Information Before Storage or TransferCWE-706Use of Incorrectly-Resolved Name or Reference

Risk Scores

CVSS 3.1
5.0/10
Medium · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Affected Products

VendorProductVersionsPlatforms
GitLabvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,366 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›