VYPR
High severity7.5NVD Advisory· Published Jul 29, 2026· Updated Aug 3, 2026

CVE-2026-15975

CVE-2026-15975

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Range: from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=11.8.0,<19.0.5
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=11.8.0,<19.0.5
    • cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:community:*:*:*
    • cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*
  • osv-coords
    Range: >= 11.8.0, < 19.0.5

Patches

Vulnerability mechanics

References

1

News mentions

2