Database/Control plane, storage & DevOps
GitLab CE/EE: malformed CSV import lets an authenticated user stall Sidekiq workers
Impact
CSV import did not properly validate file structure, so an authenticated user could submit a crafted CSV and deny service to Sidekiq workers. Sidekiq is the single background queue behind everything GitLab does asynchronously, so starving it stops CI pipeline scheduling, container-registry housekeeping and webhook delivery for the whole instance, not just the project the file was uploaded to. For an operator whose fleet builds and ships images through self-managed GitLab, that is a build and deploy outage of the fleet's software supply chain. Availability only - no data disclosure or code execution is claimed - and it needs a login, so the realistic actor is an internal user or a compromised low-privilege account.
Who can reach it
Any authenticated GitLab user who can import a CSV into a project. Network-reachable on the GitLab web endpoint. GitLab.com is operated by the vendor; this matters for self-managed instances.
What to do
Upgrade self-managed GitLab to 18.8.9, 18.9.5 or 18.10.3 per the advisory (all versions from 11.7 are affected), which is the standard GitLab upgrade plus a restart of the web and Sidekiq services. If an upgrade cannot be scheduled, restrict who can import CSV files and monitor Sidekiq queue depth so a stall is caught before it silently blocks pipelines.
References
Related entries
- PostgreSQL pgcrypto: PGP functions emit recoverable cleartext when OpenSSL disables the cipherCVE-2026-14663 · PostgreSQL pgcrypto (pgp_sym_encrypt / pgp_pub_encrypt family)Medium
- Keycloak: authenticated user can exhaust server memory via unbounded Prometheus metric labelsCVE-2026-16100 · Keycloak (user-event Prometheus metrics)Medium
- open-iscsi iscsiuio (DHCPv6 handling): Integer underflow and out-of-bounds read in iscsiuio's DHCPv6 handlingCVE-2026-18727 · open-iscsi iscsiuio (DHCPv6 handling)Medium
- Grafana: injected timeGroup macro in a SQL query exhausts memory and kills the server processCVE-2026-19475 · Grafana SQL data sources (regex macro parsing, timeGroup injected via WHERE clause)Medium
- lldpd (802.1Q VLAN tag stripping in lldpd_decode): lldpd strips 802.1Q VLAN tags by memmove-ing the frame payload fourCVE-2026-46433 · lldpd (802.1Q VLAN tag stripping in lldpd_decode)Medium
- Apache Airflow: Bulk Variables API skips key-based redaction, returning JSON variable secrets in cleartextCVE-2026-48828 · Apache Airflow (Bulk Variables API, secrets masker key-based redaction)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.