CVE-2026-15975: Allocation of Resources Without Limits or Throttling in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.0.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15975?
The severity of CVE-2026-15975 is classified as high with a score of 7.5.
How do I fix CVE-2026-15975?
To fix CVE-2026-15975, upgrade GitLab CE/EE to versions 19.0.5, 19.1.3, or 19.2.1 or later.
What type of vulnerability is CVE-2026-15975?
CVE-2026-15975 is an allocation of resources without limits or throttling vulnerability.
What impact does CVE-2026-15975 have on GitLab?
CVE-2026-15975 could allow an unauthenticated user to cause a denial of service due to insufficient resource throttling.
Which versions of GitLab are affected by CVE-2026-15975?
CVE-2026-15975 affects GitLab CE/EE versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1.