GPU VulnDB

Database/Control plane, storage & DevOps

GitLab CE/EE: integer overflow compiling a crafted CI/CD regular expression gives code execution on the server

CVSS 9.9CVE-2026-93577Control plane, storage & DevOpscurated

Impact

A separate flaw from the double free in the same patch release: compiling a crafted regular expression from a CI/CD configuration overflows an integer and lets an authenticated user run code on the GitLab server, with scope marked as changed and availability fully impacted. The consequence for a GPU datacenter is the same as any CI-plane compromise - control of the images, charts and deployment credentials that reach GPU nodes, plus whatever cluster tokens the runners hold. It is listed separately because the mechanism and code path differ from CVE-2026-89078 even though the fixed versions coincide.

Who can reach it

Any authenticated GitLab user who can commit or edit a CI/CD configuration in a project they can write to. Remote, low privilege, no user interaction.

What to do

Upgrade to GitLab 19.2.7, 19.3.3 or 19.4.1 and restart the GitLab services - the same patch release that fixes CVE-2026-89078, so one maintenance window covers both. No node reboot needed; plan a brief CI outage and audit runner token use if the instance was broadly reachable.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.