Database/Control plane, storage & DevOps
GitLab CE/EE: authenticated user can stall background job processing via missing object count limits
Impact
An authenticated user can, under conditions the advisory does not detail, submit work that lacks an object count limit and exhaust GitLab's background job processing. Background jobs are what run pipelines, mirror repositories, deliver webhooks and process artifacts, so the visible effect is that CI stops moving while the web UI still answers. On a fleet where GitLab pipelines gate model builds and deployment to GPU nodes, this is a build-and-deploy outage rather than a data exposure - confidentiality and integrity are unaffected per the vendor scoring. The record gives no detail on which object type is unbounded, so treat the trigger as unknown.
Who can reach it
Any authenticated GitLab user with network access to the instance; no elevated project or admin role is stated as required.
What to do
Upgrade to GitLab 19.3.1, 19.2.5 or 19.1.7 depending on branch; all versions from 12.8 are affected. Package upgrade plus a restart of the GitLab services, notably Sidekiq - no node drain or reboot. GitLab.com already runs the patched version.
References
Related entries
- Schneider Electric Data Center Expert - SOAP service endpoints: XML external entity processing on DCE SOAP endpointsCVE-2026-8045 · Schneider Electric Data Center Expert - SOAP service endpointsMedium
- Ceph (Python bindings, IMAP4_SSL/SMTP_SSL TLS clients): Ceph's Python code constructs imaplib.IMAP4_SSL andNCVD-2024-010-ceph-python-bindings-imap4-ssl-s · Ceph (Python bindings, IMAP4_SSL/SMTP_SSL TLS clients)Medium
- rclone (serve s3): Path traversal in rclone's S3 gateway lets a caller read and overwrite files above the served root.NCVD-2026-042-rclone-serve-s3 · rclone (serve s3)Medium
- KubeEdge CloudHub (viaduct packer, pkg/viaduct/pkg/packer): ONE COMPROMISED EDGE NODE TAKES DOWN CLOUD-EDGENCVD-2026-053-kubeedge-cloudhub-viaduct-packer · KubeEdge CloudHub (viaduct packer, pkg/viaduct/pkg/packer)Medium
- Ansible Automation Platform images: group-writable /etc/passwd lets a container user become root in-containerCVE-2025-57847 · Red Hat Ansible Automation Platform container images (/etc/passwd permissions)Medium
- galaxy_ng: namespace avatar URL is fetched unchecked, giving SSRF into internal and metadata endpointsCVE-2026-79717 · galaxy_ng (Ansible Galaxy / Automation Hub server, namespace avatar fetch worker)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.