Race condition in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2024-11222
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote user to perform actions in the context of another user\'s merge request commit.
The vulnerability exists due to a race condition in merge request pipeline creation when creating pipelines. A remote user can exploit the race condition to perform actions in the context of another user\'s merge request commit.
User interaction is required.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2024-11222
GitLab Enterprise Edition - addressed in versions 19.1.8, 19.2.6, 19.3.2