GPU VulnDB

Database/Control plane, storage & DevOps

GitLab CE/EE: Terraform state upload parameters let a project user read server files or DoS the instance

CVSS 6.8CVE-2026-3855Control plane, storage & DevOpscurated

Impact

Improper parameter validation in the Terraform state upload endpoint lets an authenticated user with project-level permissions read restricted file contents on the GitLab server, or cause denial of service. On a self-managed instance this is file disclosure from the host that holds the infrastructure-as-code state for the cluster itself, plus a way for a low-privileged project member to take the instance down. GitLab's advisory does not enumerate which paths are reachable; treat anything readable by the GitLab service account as in play.

Who can reach it

Authenticated user holding project-level permissions on the instance, over the network. Attack complexity is rated high, so exploitation is not trivial.

What to do

Upgrade to GitLab 19.1.8, 19.2.6 or 19.3.2 (affected: 18.2.7 onward). Self-managed: patch and restart GitLab. GitLab.com is already patched.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.