CRITICAL
9.9 CVE-2026-89078 Published 24 Sept 2026
GitLab CI/CD Regex Parsing Double Free Code Execution Vulnerability
Worried this affects your website?
GitLab CE/EE has remediated a double free vulnerability that could allow an authenticated user to execute arbitrary code on the GitLab server.
The issue occurs when parsing a specially crafted regular expression in a CI/CD configuration.
- Affected versions: all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1.
- Exploitation requires certain conditions and an authenticated user.
Reference: CVE-2026-89078 on NVD
← Back to Security News