CVE-2024-1736: GitLab

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue has been discovered in GitLab CE/EE affecting all versions prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's CI/CD pipeline editor could allow for denial of service attacks through maliciously crafted configuration files.

Affected products

  • GitLab GitLab: before 16.10.7 (fixed in 16.10.7); from 16.11.0, before 16.11.4 (fixed in 16.11.4); from 17.0.0, before 17.0.2 (fixed in 17.0.2)

Published 2024-06-12. Last modified 2026-06-17.