Database/Control plane, storage & DevOps
GitLab EE: crafted project export import overflows the Advanced Search Unicode buffer for RCE
Impact
An authenticated GitLab user can import a specially crafted Git project export whose content overflows the Unicode conversion buffer used by Advanced Search indexing, reaching remote code execution under certain conditions. The CVSS vector reports a scope change, meaning execution escapes the affected component's boundary. A self-hosted GitLab is usually the CI/CD and registry hub for a GPU fleet: code execution there exposes runner tokens, registry credentials, deploy keys and cluster service accounts, which is a route into the nodes themselves rather than an isolated application compromise. Attack complexity is rated high, so this is not a drive-by, but any user able to import a project is a candidate.
Who can reach it
Any authenticated GitLab user with permission to import a project. Affects EE 12.3 through 19.1.8, 19.2 before 19.2.6 and 19.3 before 19.3.2, and requires Advanced Search indexing to be in play.
What to do
Upgrade GitLab EE to 19.1.8, 19.2.6 or 19.3.2 or later. This is the normal GitLab upgrade and service restart on the application hosts - no GPU node drain or reboot - but budget for the usual background migrations. If you cannot patch immediately, restrict who may import projects and consider pausing Advanced Search indexing until the upgrade lands.
References
Related entries
- Renovate: unescaped Gradle distributionUrl gives a repository command execution as the Renovate userCVE-2026-88886 · Renovate self-hosted (Gradle Wrapper manager, distributionUrl)High
- Renovate: unescaped Maven Wrapper distributionType lets a repository run commands in the botCVE-2026-88889 · Renovate self-hosted (Maven Wrapper manager, distributionType)High
- Ceph RGW (STS session tokens): Any tenant holding one ordinary STS session token can edit it into RGW superuser. RGWNCVD-2026-040-ceph-rgw-sts-session-tokens · Ceph RGW (STS session tokens)High
- CloudNativePG (role password handling, pg_stat_statements exposure): CREDENTIAL DISCLOSURE ACROSS THE TENANT BOUNDARYNCVD-2026-049-cloudnativepg-role-password-hand · CloudNativePG (role password handling, pg_stat_statements exposure)High
- IBM Spectrum Scale Container Native Storage Access: A local user obtains root privileges through the Spectrum ScaleCVE-2022-41736 · IBM Spectrum Scale Container Native Storage AccessHigh
- ConnectWise ScreenConnect: Path traversal enabling remote code executionCVE-2024-1708 · ConnectWise ScreenConnectHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.