
PEACH
Un framework di isolamento del tenant
CVE-2026-93577 is a critical Remote Code Execution (RCE) vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) caused by an integer overflow in the CI/CD configuration regular expression compiler. It affects all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. The vulnerability was published on September 24, 2026, and GitLab has released patches addressing the issue. It carries a CVSS v3.1 base score of 9.9 (Critical) (GitHub Advisory, GitLab Patch Release).
The root cause is an integer overflow or wraparound (CWE-190, mapped to CAPEC-92: Forced Integer Overflow) that occurs when GitLab's CI/CD pipeline engine compiles a specially crafted regular expression supplied in a pipeline configuration file (e.g., .gitlab-ci.yml). An authenticated user with access to define or modify CI/CD configurations can submit a malicious regex that triggers the overflow during compilation, leading to memory corruption and ultimately arbitrary code execution on the GitLab server. The attack vector is network-based, requires low privileges (authenticated user), no user interaction, and has low attack complexity, with scope change indicating impact beyond the vulnerable component itself (GitHub Advisory, GitLab Patch Release).
Successful exploitation grants an attacker arbitrary code execution on the GitLab server with the privileges of the GitLab service account, resulting in complete compromise of confidentiality, integrity, and availability. An attacker could exfiltrate source code repositories, secrets, CI/CD credentials, and other sensitive data hosted on the instance, as well as modify or destroy data and disrupt service availability. The changed scope indicates the impact extends beyond the GitLab application itself, potentially enabling lateral movement into connected infrastructure such as deployment targets, container registries, or integrated cloud environments (GitHub Advisory, GitLab Patch Release).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability was reported via HackerOne (report #3995696) and is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.43–0.55%, placing it in the 44th percentile for exploitation probability within 30 days. The NVD SSVC assessment classifies exploitation as "none" at time of publication, though the critical severity and low exploitation complexity make it a high-priority patching target (GitHub Advisory).
/help or API /api/v4/version if accessible)..gitlab-ci.yml)..gitlab-ci.yml file in a project to include a specially crafted regular expression designed to trigger an integer overflow in GitLab's regex compilation engine during pipeline processing.production.log, sidekiq.log) showing pipeline jobs with unusual or excessively complex regular expressions in CI/CD configuration; unexpected errors or crashes in the regex compilation phase of pipeline processing./bin/bash, curl, wget, python, nc) not associated with normal pipeline runners.git or gitlab service account, or presence of web shells in accessible directories..gitlab-ci.yml) containing highly complex, deeply nested, or obfuscated regular expression patterns, especially in projects where such complexity is unexpected.GitLab has released patched versions addressing this vulnerability: 19.2.7, 19.3.3, and 19.4.1. All self-managed GitLab CE/EE administrators running affected versions (19.2.x < 19.2.7, 19.3.x < 19.3.3, or 19.4.0) should upgrade immediately (GitLab Patch Release). As a temporary workaround prior to patching, restrict CI/CD pipeline configuration permissions to trusted users only by limiting Developer-level access and enforcing protected branch/pipeline policies. Additionally, monitor for suspicious CI/CD configuration changes and unusual server-side process activity as described in the IOCs section.
The vulnerability received significant media coverage given its critical 9.9 CVSS score. Security outlets including CyberSecurityNews, Heise, Cryptika, and LinuxSecurity reported on the flaw, noting it as one of two CVSS 9.9-rated authenticated RCE vulnerabilities patched in the same GitLab release cycle (CyberSecurityNews, Heise). Community discussion appeared on Mastodon (infosec.exchange) and Reddit, with practitioners emphasizing the urgency of patching self-managed instances. SecurityOnline.info highlighted the patch release as a critical update requiring immediate action (SecurityOnline).
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."