5.3
CVE-2026-13113
- EPSS 0.2%
- Veröffentlicht 29.07.2026 19:00:31
- Zuletzt bearbeitet 03.08.2026 13:29:14
- Erkennungen
Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to merge code into a protected branch without the required approvals due to a race condition in approval rule processing.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.101 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
|
| cve@gitlab.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/
https://gitlab.com/gitlab-org/gitlab/-/work_items/597838