CVE-2026-1458: Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service by uploading malicious files.
Other sources
GitLab has remediated an issue that, under certain conditions, could have allowed an unauthenticated user to cause denial of service by uploading specifically crafted files.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-1458?
CVE-2026-1458 is classified as a Denial of Service vulnerability affecting specific versions of GitLab.
How do I fix CVE-2026-1458?
To remediate CVE-2026-1458, upgrade GitLab to versions 18.6.6, 18.7.4, or 18.8.4.
Which versions are affected by CVE-2026-1458?
CVE-2026-1458 affects GitLab CE/EE versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4.
Can an unauthenticated user exploit CVE-2026-1458?
Yes, CVE-2026-1458 allows an unauthenticated user to potentially cause a denial of service in affected GitLab versions.
Has CVE-2026-1458 been fixed in GitLab?
Yes, CVE-2026-1458 has been fixed in GitLab versions 18.6.6, 18.7.4, and 18.8.4.