GPU VulnDB

Database/Control plane, storage & DevOps

GitLab CE/EE: malformed CSV import lets an authenticated user stall Sidekiq workers

CVSS 6.5CVE-2026-1403Control plane, storage & DevOpscurated

Impact

CSV import did not properly validate file structure, so an authenticated user could submit a crafted CSV and deny service to Sidekiq workers. Sidekiq is the single background queue behind everything GitLab does asynchronously, so starving it stops CI pipeline scheduling, container-registry housekeeping and webhook delivery for the whole instance, not just the project the file was uploaded to. For an operator whose fleet builds and ships images through self-managed GitLab, that is a build and deploy outage of the fleet's software supply chain. Availability only - no data disclosure or code execution is claimed - and it needs a login, so the realistic actor is an internal user or a compromised low-privilege account.

Who can reach it

Any authenticated GitLab user who can import a CSV into a project. Network-reachable on the GitLab web endpoint. GitLab.com is operated by the vendor; this matters for self-managed instances.

What to do

Upgrade self-managed GitLab to 18.8.9, 18.9.5 or 18.10.3 per the advisory (all versions from 11.7 are affected), which is the standard GitLab upgrade plus a restart of the web and Sidekiq services. If an upgrade cannot be scheduled, restrict who can import CSV files and monitor Sidekiq queue depth so a stall is caught before it silently blocks pipelines.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.