Intel

AIKIDO-2026-270468

gitlab-ce is vulnerable to Buffer Overflow

Buffer OverflowCVE-2026-88765 Published 3 days ago

85

High Risk

This Affects:

OSgitlab-ce
12.3.0 - 19.1.7
Fixed in 19.1.8
19.2.0 - 19.2.5
Fixed in 19.2.6
19.3.0 - 19.3.1
Fixed in 19.3.2
Are you affected? Scan for Free

TL;DR

Advanced Search indexing uses a Unicode conversion wrapper that can overflow when processing a specially crafted Git project export. An authenticated user who can import such an export can achieve remote code execution on the GitLab server. The fix bounds the Unicode conversion buffer so oversized export content cannot overflow it.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and Advanced Search indexing is enabled.

Background info

gitlab-ce is vulnerable to Buffer Overflow in versions 12.3.0 - 19.1.7, 19.2.0 - 19.2.5 and 19.3.0 - 19.3.1.

How to fix this

Upgrade the gitlab-ce library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform