CVE-2026-0958: Interpretation Conflict in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through memory or CPU exhaustion by bypassing JSON validation middleware limits.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to cause denial of service through memory or CPU exhaustion by bypassing JSON validation middleware limits.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-0958?
CVE-2026-0958 has been classified with a severity that indicates it may lead to denial of service if exploited.
How do I fix CVE-2026-0958?
To fix CVE-2026-0958, update your GitLab CE or EE to version 18.6.6, 18.7.4, or 18.8.4 or later.
What versions are affected by CVE-2026-0958?
CVE-2026-0958 affects GitLab CE and EE versions from 18.4 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4.
Can unauthenticated users exploit CVE-2026-0958?
Yes, CVE-2026-0958 can allow unauthenticated users to exploit the vulnerability and cause denial of service.
What actions should be taken if I cannot update GitLab to fix CVE-2026-0958?
If you cannot update GitLab, implement network level protections to mitigate potential exploitation of CVE-2026-0958.