{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T08:25:08.305","vulnerabilities":[{"cve":{"id":"CVE-2026-1387","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:04.547","lastModified":"2026-06-17T10:15:41.383","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to cause Denial of Service by uploading a malicious file and repeatedly querying it through GraphQl."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afecta a todas las versiones desde la 15.6 anterior a la 18.6.6, la 18.7 anterior a la 18.7.4, y la 18.8 anterior a la 18.8.4 que podría haber permitido a un usuario autenticado causar una denegación de servicio al subir un archivo malicioso y consultarlo repetidamente a través de GraphQl."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"15.6","lessThan":"18.6.6","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-11T21:17:22.725712Z","id":"CVE-2026-1387","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"15.6.0","versionEndExcluding":"18.6.6","matchCriteriaId":"3F0CFD5D-2A9D-49FD-A315-392CB1E1277F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/587546","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3515994","source":"cve@gitlab.com","tags":["Broken Link"]}]}}]}