GPU VulnDB

Database/Control plane, storage & DevOps

GitLab EE: crafted project export import overflows the Advanced Search Unicode buffer for RCE

CVSS 8.5CVE-2026-88765Control plane, storage & DevOpscurated

Impact

An authenticated GitLab user can import a specially crafted Git project export whose content overflows the Unicode conversion buffer used by Advanced Search indexing, reaching remote code execution under certain conditions. The CVSS vector reports a scope change, meaning execution escapes the affected component's boundary. A self-hosted GitLab is usually the CI/CD and registry hub for a GPU fleet: code execution there exposes runner tokens, registry credentials, deploy keys and cluster service accounts, which is a route into the nodes themselves rather than an isolated application compromise. Attack complexity is rated high, so this is not a drive-by, but any user able to import a project is a candidate.

Who can reach it

Any authenticated GitLab user with permission to import a project. Affects EE 12.3 through 19.1.8, 19.2 before 19.2.6 and 19.3 before 19.3.2, and requires Advanced Search indexing to be in play.

What to do

Upgrade GitLab EE to 19.1.8, 19.2.6 or 19.3.2 or later. This is the normal GitLab upgrade and service restart on the application hosts - no GPU node drain or reboot - but budget for the usual background migrations. If you cannot patch immediately, restrict who may import projects and consider pausing Advanced Search indexing until the upgrade lands.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.