Gitlab · Gitlab Ce/Ee · CVE-2026-0958
**Name of the Vulnerable Software and Affected Versions**
GitLab CE/EE versions 18.4 through 18.6.5
GitLab CE/EE versions 18.7 through 18.7.3
GitLab CE/EE versions 18.8 through 18.8.3
**Description**
An unauthenticated user could potentially cause a denial of service by exhausting memory or CPU resources. This is achieved by bypassing limits within the JSON validation middleware.
**Recommendations**
Update GitLab CE/EE to version 18.6.6 or later.
Update GitLab CE/EE to version 18.7.4 or later.
Update GitLab CE/EE to version 18.8.4 or later.