Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities Web Discovery

NVD - CVE-2026-1456

  • What: A denial-of-service vulnerability has been discovered in GitLab CE/EE.
  • Impact: An unauthenticated user can cause CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview.
  • Affected: GitLab CE/EE versions from 18.7 before 18.7.4, and 18.8 before 18.8.4.
  • CVE: CVE-2026-1456
Read Full Article →

Vulnerabilities CVE-2026-1456 Detail Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CNA: GitLab Inc. Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS 2.0 Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected] . URL Source(s) Tag(s) https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/ GitLab Inc. Release Notes Vendor Advisory https://gitlab.com/gitlab-org/gitlab/-/issues/587688 GitLab Inc. Broken Link Issue Tracking https://hackerone.com/reports/3517928 GitLab Inc. Permissions Required Weakness Enumeration CWE-ID CWE Name Source CWE-770 Allocation of Resources Without Limits or Throttling GitLab Inc. Known Affected Software Configurations Switch to CPE 2.2 CPEs loading, please wait. Change History 2 change records found show changes Initial Analysis by NIST 2/12/2026 4:39:23 PM Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Added CPE Configuration OR *cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* versions from (including) 18.7.0 up to (excluding) 18.7.4 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* versions from (including) 18.8.0 up to (excluding) 18.8.4 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* versions from (including) 18.7.0 up to (excluding) 18.7.4 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* versions from (including) 18.8.0 up to (excluding) 18.8.4 Added Reference Type GitLab Inc.: https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/ Types: Release Notes, Vendor Advisory Added Reference Type GitLab Inc.: https://gitlab.com/gitlab-org/gitlab/-/issues/587688 Types: Broken Link, Issue Tracking Added Reference Type GitLab Inc.: https://hackerone.com/reports/3517928 Types: Permissions Required New CVE Received from GitLab Inc. 2/11/2026 7:16:04 AM Action Type Old Value New Value Added Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview. Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Added CWE CWE-770 Added Reference https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/ Added Reference https://gitlab.com/gitlab-org/gitlab/-/issues/587688 Added Reference https://hackerone.com/reports/3517928 Quick Info CVE Dictionary Entry: CVE-2026-1456 NVD Published Date: 02/11/2026 NVD Last Modified: 02/12/2026 Source: GitLab Inc.

Share this article