Integer overflow in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-93577
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the GitLab server.
The vulnerability exists due to an integer overflow in the regular expression compiler when compiling a specially crafted regular expression in a CI/CD configuration. A remote user can submit a specially crafted regular expression to execute arbitrary code on the GitLab server.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2026-93577
GitLab Enterprise Edition - addressed in versions 19.2.7, 19.3.3, 19.4.1