CVE-2026-1403: Denial of Service issue in CSV import impacts GitLab CE/EE
Published Apr 8, 2026
·Updated
GitLab has remediated an issue that when importing CSV files could have allowed an authenticated user to cause denial of service to Sidekiq workers due to improper validation of CSV file structure.
Affected Software
1 affected componentFixes available
GitLab GitLab>=11.7<18.8.9, >=18.9<18.9.5, >=18.10<18.10.3
18.8.918.9.518.10.3
Event History
Apr 22, 2026
CVE Published
via GitLab·01:52 PM
Data Sourced
via GitLab·01:52 PM
DescriptionSeverityAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.