VYPR
High severity7.5NVD Advisory· Published Mar 11, 2026· Updated Jun 17, 2026

CVE-2026-1069

CVE-2026-1069

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by sending specially crafted GraphQL requests due to uncontrolled recursion under certain circumstances.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • GitLab Inc./GitLabv54 versions
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 18.9
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=18.9.0,<18.9.2
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=18.9.0,<18.9.2
    • (no CPE)range: <18.9.2
  • Range: <18.9.2
  • osv-coords
    Range: >= 18.9.0, < 18.9.2

Patches

Vulnerability mechanics

References

2

News mentions

1