CVE-2026-89078

CVE & Vulnerabilities · September 26, 2026

CVE & Vulnerabilities·nvd.nist.gov

GitLab has patched a serious remote-code-execution bug, CVE-2026-89078, caused by a double-free memory error when the server parses a maliciously crafted regular expression inside a CI/CD pipeline configuration. Exploiting it would let a logged-in user run arbitrary code on the GitLab server. The fix landed in GitLab CE/EE releases 19.2.7, 19.3.3, and 19.4.1, so admins on those version branches should upgrade right away.

// source: nvd.nist.gov ↗

← Back to Blog