GPU VulnDB

Database/Control plane, storage & DevOps

GitLab CE/EE: double free parsing a crafted CI/CD regular expression gives code execution on the server

CVSS 9.9CVE-2026-89078Control plane, storage & DevOpscurated

Impact

An authenticated GitLab user who can supply a CI/CD configuration can trigger a double free in the regular-expression parser and execute arbitrary code on the GitLab server itself. The CVSS vector marks the scope as changed, meaning the compromise reaches beyond the GitLab process. For a GPU fleet this is a build-and-deploy plane compromise: whoever controls the CI server controls the container images, Helm charts and runner credentials that land on GPU nodes, and GitLab runners themselves often hold registry and cluster tokens. The privilege needed is low - any user with push or project-configuration rights.

Who can reach it

Any authenticated GitLab user able to commit or edit a CI/CD configuration file in a project they can write to. Network-reachable; no administrator role required.

What to do

Upgrade to GitLab 19.2.7, 19.3.3 or 19.4.1 per the 19.4.1 patch release and restart the GitLab services. Self-managed operators should treat this as a same-day patch for an internet-reachable instance; no node reboot is required, but expect a short outage of the CI plane during the upgrade and review runner job history and token use if the instance was exposed.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.