Double free in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-89078
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the GitLab server.
The vulnerability exists due to a double free in the regular expression parser when parsing a specially crafted regular expression in a CI/CD configuration. A remote user can submit a specially crafted regular expression to execute arbitrary code on the GitLab server.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2026-89078
GitLab Enterprise Edition - addressed in versions 19.2.7, 19.3.3, 19.4.1