CVE-2026-1069 is a high-severity denial-of-service vulnerability affecting GitLab CE/EE versions from 18.9 before 18.9.2. An unauthenticated attacker can exploit this by sending specially crafted GraphQL requests, leading to uncontrolled recursion and system unavailability. With a CVSS score of 7.5, it has a network attack vector, low attack complexity, and requires no privileges or user interaction, resulting in a high impact on availability. There is currently no evidence of active exploitation, and public exploit code is not available in common databases like Metasploit or ExploitDB. Community discussion and media coverage regarding this vulnerability are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 18.9, < 18.9.2CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 18.9.0, < 18.9.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 18.9.0, < 18.9.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.