Vulnerability intelligence
CVE-2026-15975
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions.
CVSS Score
7.5
High
EPSS — Exploit Probability
0.5%
Riskier than 39% of all CVEs · checked 2026-09-11
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Jul 30, 2026 · latest Jul 30, 2026
Coverage timeline
-
GitLab patches critical flaw CVE-2026-6267 allowing data accesssecurityonline.info · Jul 30, 2026