gitlab-ce is vulnerable to Remote Code Execution (RCE)
99
Critical Risk
The CI/CD configuration regular-expression parser double-frees memory when parsing a specially crafted pattern. An authenticated user who can place that pattern in a pipeline configuration can trigger the double free and execute arbitrary code on the GitLab server. The fix corrects lifetime handling so a parsed pattern cannot free the same allocation twice.
You are affected if you are using a version that falls within the vulnerable range and authenticated users can create or edit CI/CD configuration.
gitlab-ce is vulnerable to Remote Code Execution (RCE) in versions 19.2.0 - 19.2.6, 19.3.0 - 19.3.2 and 19.4.0 - 19.4.0.
Upgrade the gitlab-ce and/or the gitlab-ee library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.