CVE-2026-89078 - Double Free issue in Regular Expression Parser impacts GitLab CE/EE
GitLab has remediated an issue that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration.
Impacted Versions: GitLab CE/EE: all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1
CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L)
CVE-2026-93577 - Integer Overflow issue in Regular Expression Compiler impacts GitLab CE/EE
GitLab has remediated an issue that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.
Impacted Versions: GitLab CE/EE: all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1
CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
GitLab Critical Patch Release: 19.4.1, 19.3.3, 19.2.7
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/?nav=19.4.1
Не, ну реально радуют уже второй раз подряд, в этот раз 9.9+9.9, в прошлый 9.9+10 🌝
https://t.me/tech_b0lt_Genona/6966