Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that when importing CSV files could have allowed an authenticated user to cause denial of service to Sidekiq workers due to improper validation of CSV file structure.
Published: 2026-10-07
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

GitLab’s CSV import processing lacks proper validation, allowing an authenticated user to craft an improper CSV file that, when ingested, can cause Sidekiq workers to terminate, leading to a denial of service that affects background job processing. This weakness falls under the allocation of resources without limits weakness.

Affected Systems

GitLab Community and Enterprise Editions, all releases from 11.7 up to 18.8.8, 18.9.0 to 18.9.4, and 18.10.0 to 18.10.2. The vulnerability has been fixed in GitLab 18.8.9, 18.9.5, and 18.10.3 and later releases.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. Exploitation requires the attacker to be an authenticated user with permission to import CSV files, which is a common capability in many environments. The EPSS score is not available, so the current exploitation probability cannot be estimated, and the vulnerability is not listed in the CISA KEV catalog. The attack likely occurs locally or remotely from a user that has authenticated into GitLab’s web interface, using the CSV import interface to trigger the failure of Sidekiq workers.

Generated by OpenCVE AI on October 7, 2026 at 21:51 UTC.

Remediation

Vendor Solution

Upgrade to versions 18.8.9, 18.9.5, 18.10.3 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab to a version that includes the fix (18.8.9 or newer, 18.9.5 or newer, 18.10.3 or newer).
  • Restrict CSV import functionality to trusted users if upgrade not immediately possible.
  • Monitor Sidekiq worker logs for signs of crashes or repeated failures.

Generated by OpenCVE AI on October 7, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that when importing CSV files could have allowed an authenticated user to cause denial of service to Sidekiq workers due to improper validation of CSV file structure.
Title Allocation of Resources Without Limits or Throttling in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-770
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-07T20:32:41.160Z

Reserved: 2026-01-23T23:03:49.896Z

Link: CVE-2026-1403

cve-icon Vulnrichment

Updated: 2026-10-07T20:32:36.504Z

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:15.863

Modified: 2026-10-07T21:17:15.863

Link: CVE-2026-1403

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T22:00:06Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling