GPU VulnDB

Database/Control plane, storage & DevOps

GitLab CE/EE: authenticated user can stall background job processing via missing object count limits

CVE-2026-77801Control plane, storage & DevOpscurated

Impact

An authenticated user can, under conditions the advisory does not detail, submit work that lacks an object count limit and exhaust GitLab's background job processing. Background jobs are what run pipelines, mirror repositories, deliver webhooks and process artifacts, so the visible effect is that CI stops moving while the web UI still answers. On a fleet where GitLab pipelines gate model builds and deployment to GPU nodes, this is a build-and-deploy outage rather than a data exposure - confidentiality and integrity are unaffected per the vendor scoring. The record gives no detail on which object type is unbounded, so treat the trigger as unknown.

Who can reach it

Any authenticated GitLab user with network access to the instance; no elevated project or admin role is stated as required.

What to do

Upgrade to GitLab 19.3.1, 19.2.5 or 19.1.7 depending on branch; all versions from 12.8 are affected. Package upgrade plus a restart of the GitLab services, notably Sidekiq - no node drain or reboot. GitLab.com already runs the patched version.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.