High severity7.5NVD Advisory· Published Jul 29, 2026· Updated Aug 3, 2026
CVE-2026-15975
CVE-2026-15975
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- Range: from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=11.8.0,<19.0.5
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=11.8.0,<19.0.5
- cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*
Patches
Vulnerability mechanics
References
1- docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/nvdRelease NotesVendor Advisory
News mentions
2- GitLab Fixes 13 Security Flaws That Can Leak Data, Alter Pipelines, and Crash ServersCyber Security News · Jul 30, 2026
- GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5GitLab Security Releases · Jul 29, 2026