MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
Published Feb 25, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.46%
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an authenticated user to cause denial of service by exploiting a Bitbucket Server import endpoint via repeatedly sending large responses.
Affected products
-
- Version 11.2StatusaffectedConstraints<18.7.5
- Version 18.8StatusaffectedConstraints<18.8.5
- Version 18.9StatusaffectedConstraints<18.9.1
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 18.7.5, 18.8.5, 18.9.1 or above.
Weaknesses (1)
References (3)
- https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-released/ Release NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-8742 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/work_items/570554 Broken Link
| Link | Providers | Tags |
|---|---|---|
| https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-released/ | Release NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-8742 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/work_items/570554 | Broken Link |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Feb 25, 2026
Updated Feb 26, 2026
Reserved Feb 20, 2026
Link CVE-2026-2845
CISA Vulnrichment
Updated Feb 26, 2026
ENISA EUVD
EUVD-2026-8742 Assigner GitLab
Published Feb 25, 2026
Updated Feb 26, 2026
Exploited since n/a
Link EUVD-2026-8742