CVE-2026-77801: GitLab

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, could have allowed an authenticated user to cause a denial of service affecting background job processing, due to missing object count limits.

Affected products

  • GitLab GitLab: from 12.8.0, before 19.1.7 (fixed in 19.1.7); from 19.2.0, before 19.2.5 (fixed in 19.2.5); version 19.3.0 only

Published 2026-08-26. Last modified 2026-08-31.