
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1388 is a Regular Expression Denial of Service (ReDoS) vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) affecting the merge request endpoint. It allows unauthenticated attackers to cause denial of service by sending specially crafted input under certain conditions. The vulnerability affects all GitLab CE/EE versions from 9.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1. It was disclosed and patched on February 25, 2026, with a CVSS v3.1 base score of 7.5 (High) (GitLab Advisory, Red Hat CVE).
The root cause is classified as CWE-1333 (Inefficient Regular Expression Complexity), also mapped to CAPEC-492 (Regular Expression Exponential Blowup). An attacker can exploit this by sending specially crafted input to the GitLab merge request endpoint, triggering catastrophic backtracking in a vulnerable regular expression pattern, which causes the server process to consume excessive CPU resources. No authentication, user interaction, or elevated privileges are required, and attack complexity is low. The vulnerability was reported by researcher "sim4n6" through GitLab's HackerOne bug bounty program (GitLab Advisory, Red Hat CVE).
Successful exploitation results in a high availability impact, potentially rendering the GitLab instance unresponsive or unavailable to legitimate users. There is no confidentiality or integrity impact — the attack is purely a denial-of-service condition. Given the extremely broad version range affected (9.2 through current), a large number of self-managed GitLab deployments could be targeted, disrupting development workflows and CI/CD pipelines (GitLab Advisory).
As of the time of disclosure, no public proof-of-concept exploit code is known to exist, and there is no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.041%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Despite the low exploitation evidence, the attack requires no authentication and has low complexity, making it a straightforward target if a PoC were to emerge (Red Hat CVE).
/api/v4/version if accessible, or the GitLab UI footer).production.log) showing repeated requests to merge request endpoints with high response times or timeouts; Unicorn/Puma worker timeout errors or process restarts in unicorn_stderr.log or puma_stderr.log./var/log/syslog or journalctl).GitLab has released patched versions addressing this vulnerability: 18.7.5 (for versions 9.2–18.7.x), 18.8.5 (for 18.8.x), and 18.9.1 (for 18.9.x). GitLab strongly recommends that all self-managed installations upgrade to one of these versions immediately. GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take action. No configuration-based workaround is documented; upgrading is the only recommended remediation (GitLab Advisory).
GitLab issued a patch release advisory on February 25, 2026, classifying the issue as High severity and strongly recommending immediate upgrades for all self-managed installations. The vulnerability was reported through GitLab's HackerOne bug bounty program by researcher "sim4n6". Social media activity was limited, with some mentions on Mastodon and Bluesky aggregating the advisory, but no significant controversy or widespread community discussion was observed (GitLab Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."