VYPR
Medium severity4.3NVD Advisory· Published Jun 11, 2026· Updated Jun 11, 2026

CVE-2026-10733

CVE-2026-10733

Description

An authenticated GitLab user can cause denial of service on the CI/CD Catalog page due to improper input sanitization in versions 17.0 to 19.0.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An authenticated GitLab user can cause denial of service on the CI/CD Catalog page due to improper input sanitization in versions 17.0 to 19.0.1.

Vulnerability

GitLab CE/EE versions from 17.0 up to but not including 18.10.8, from 18.11 up to but not including 18.11.5, and 19.0 up to but not including 19.0.2 are affected. The vulnerability lies in the CI/CD Catalog page where improper input sanitization allows an authenticated user to inject crafted input that triggers a denial of service condition [1].

Exploitation

An attacker must be an authenticated GitLab user with access to the CI/CD Catalog page. By submitting specially crafted input (e.g., in a project description or similar field that is displayed on the catalog page), the attacker can cause the page to become unresponsive or crash, effectively denying service to other users viewing the catalog [1].

Impact

Successful exploitation results in denial of service affecting the CI/CD Catalog page. Other users may be unable to view or interact with the catalog. No data confidentiality or integrity impact is indicated; the issue is limited to availability.

Mitigation

The vulnerability is fixed in GitLab versions 18.10.8, 18.11.5, and 19.0.2, released on June 10, 2026 [1]. Users are advised to upgrade to one of these patched versions. No workarounds have been provided.

AI Insight generated on Jun 11, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

1