CVE-2026-1069: Uncontrolled Recursion in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by sending specially crafted GraphQL requests due to uncontrolled recursion under certain circumstances.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to cause a denial of service condition by sending specially crafted GraphQL requests due to uncontrolled recursion under certain circumstances.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-1069?
CVE-2026-1069 is categorized as a denial of service vulnerability due to uncontrolled recursion.
How do I fix CVE-2026-1069?
To remediate CVE-2026-1069, upgrade GitLab to version 18.9.2 or later.
Which versions of GitLab are affected by CVE-2026-1069?
CVE-2026-1069 affects all versions of GitLab CE/EE from 18.9 before 18.9.2.
Can CVE-2026-1069 be exploited by authenticated users?
No, CVE-2026-1069 can be exploited by unauthenticated users through specially crafted GraphQL requests.
What impact does CVE-2026-1069 have on GitLab users?
CVE-2026-1069 allows for denial of service, which can disrupt normal operation of GitLab for users.