CVE-2026-1458Patch(gitlab / gitlab)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch gitlab gitlab systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service by uploading malicious files.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-11: 3Patch / Workaround · 2026-02-11: 2Technical Details · 2026-02-11: 302-11
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1458 Unauthenticated Denial of Service Vulnerability in GitLab CE/EE https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1458

    Post summary

    The text announces CVE-2026-1458, an unauthenticated denial‑of‑service vulnerability impacting GitLab Community and Enterprise Editions.

    0000050
    4.0K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-1458: GitLab CE/EE markdown parser flaw lets anyone crash your instance remotely, no login needed. Upgrade to 18.8.4+ asap! Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-1458 #GitLab #infosec #DevOps

    Post summary

    The advisory warns that CVE-2026-1458 can crash any GitLab instance remotely without authentication, urging users to upgrade to 18.8.4+.

    0000047
    51 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-1458 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions … https://www.cve.org/CVERecord?id=CVE-2026-1458

    Post summary

    GitLab has released a patch for CVE-2026-1458, addressing an issue that impacted multiple major versions of GitLab CE/EE under certain conditions.

    00000194
    56.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---

Explore more