CVE-2026-13113

MEDIUM

Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab

Title source: cna
STIX 2.1

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to merge code into a protected branch without the required approvals due to a race condition in approval rule processing.

Scores

CVSS v3 6.5
EPSS 0.0021
EPSS Percentile 11.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-367
Status published
Products (3)
GitLab/GitLab 17.0 - 19.0.5
GitLab/GitLab 19.1 - 19.1.3
GitLab/GitLab 19.2 - 19.2.1
Published Jul 29, 2026
Tracked Since Jul 30, 2026