CRITICAL 9.9 CVE-2026-89078 Published 24 Sept 2026

GitLab CI/CD Regex Parsing Double Free Code Execution Vulnerability

Worried this affects your website?

GitLab CE/EE has remediated a double free vulnerability that could allow an authenticated user to execute arbitrary code on the GitLab server.

The issue occurs when parsing a specially crafted regular expression in a CI/CD configuration.

  • Affected versions: all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1.
  • Exploitation requires certain conditions and an authenticated user.

Reference: CVE-2026-89078 on NVD

← Back to Security News