Intel

AIKIDO-2026-635205

gitlab-ce is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE)CVE-2026-89078 Published 5 days ago

99

Critical Risk

This Affects:

OSgitlab-ce
19.2.0 - 19.2.6
Fixed in 19.2.7
19.3.0 - 19.3.2
Fixed in 19.3.3
19.4.0 - 19.4.0
Fixed in 19.4.1
Are you affected? Scan for Free

TL;DR

The CI/CD configuration regular-expression parser double-frees memory when parsing a specially crafted pattern. An authenticated user who can place that pattern in a pipeline configuration can trigger the double free and execute arbitrary code on the GitLab server. The fix corrects lifetime handling so a parsed pattern cannot free the same allocation twice.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and authenticated users can create or edit CI/CD configuration.

Background info

gitlab-ce is vulnerable to Remote Code Execution (RCE) in versions 19.2.0 - 19.2.6, 19.3.0 - 19.3.2 and 19.4.0 - 19.4.0.

How to fix this

Upgrade the gitlab-ce and/or the gitlab-ee library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform