CVE-2026-1168
Last modified
CVE-2026-1168 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation limits in the GraphQL complexity calculation logic.. EPSS estimates a 0.64% chance of exploitation in the next 30 days.
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation limits in the GraphQL complexity calculation logic.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| GitLab | GitLab | >= 18.4.6, < 19.1.8; >= 19.2, < 19.2.6; >= 19.3, < 19.3.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-1168?
How severe is CVE-2026-1168?
How do I fix CVE-2026-1168?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-11674Use after free in Guest View in Google Chrome prior to 149.0…8.8
- CVE-2026-11675Out of bounds read in Skia in Google Chrome prior to 149.0.7…3.1
- CVE-2026-11676Insufficient validation of untrusted input in Dawn in Google…8.3
- CVE-2026-11677Race in Network in Google Chrome on Mac prior to 149.0.7827.…8.3
- CVE-2026-11678Integer overflow in libyuv in Google Chrome prior to 149.0.7…5.3
- CVE-2026-11679Use after free in Codecs in Google Chrome on Windows prior t…8.3
- CVE-2026-11680Use after free in Media in Google Chrome on Windows prior to…8.8
- CVE-2026-11681Use after free in Ozone in Google Chrome on Linux prior to 1…8.8
- CVE-2026-11682Inappropriate implementation in Views in Google Chrome on Li…8.3
- CVE-2026-11683Use after free in WebCodecs in Google Chrome prior to 149.0.…8.8
- CVE-2026-11684Insufficient policy enforcement in Network in Google Chrome …3.1
- CVE-2026-11685Inappropriate implementation in MediaCapture in Google Chrom…4.3
Are you affected by CVE-2026-1168?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
