CVE-2026-1101: Improper Validation of Specified Quantity in Input in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to cause denial of service to the GitLab instance due to improper input validation in GraphQL queries.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to cause denial of service to the GitLab instance due to improper input validation in GraphQL queries.
— GitLab
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.8.9Fixed in 18.9.5Fixed in 18.10.3 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.8.9 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.9.5 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.10.3
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-1101?
CVE-2026-1101 has a severity rating that may lead to denial of service vulnerabilities in GitLab EE.
How do I fix CVE-2026-1101?
To resolve CVE-2026-1101, upgrade your GitLab EE instance to version 18.8.9, 18.9.5, or 18.10.3 or later.
Which GitLab EE versions are affected by CVE-2026-1101?
CVE-2026-1101 affects all GitLab EE versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3.
Who is impacted by CVE-2026-1101?
Authenticated users of GitLab EE who are running affected versions may be impacted by CVE-2026-1101.
When was CVE-2026-1101 disclosed?
CVE-2026-1101 was disclosed in the GitLab release notes on April 8, 2026.