CVE-2026-1456: Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-1456?
CVE-2026-1456 is classified as a Denial of Service vulnerability allowing CPU exhaustion.
How do I fix CVE-2026-1456?
To fix CVE-2026-1456, upgrade to GitLab versions 18.7.4 or 18.8.4 or later.
Who is affected by CVE-2026-1456?
CVE-2026-1456 affects all versions of GitLab CE and EE from 18.7 before 18.7.4 and 18.8 before 18.8.4.
What kind of attack does CVE-2026-1456 facilitate?
CVE-2026-1456 allows an unauthenticated user to cause a Denial of Service through CPU exhaustion.
When was CVE-2026-1456 reported?
CVE-2026-1456 was reported prior to the patch releases in February 2026.