Skip to content
VulniPulse

GitLab Security Advisories & CVEs

76 advisories tracked · GitLab (cve@gitlab.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor GitLab CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your GitLab device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in GitLab's recent advisories.

Official source

GitLab (cve@gitlab.com CNA) via NVD

GitLab is its own CVE Numbering Authority and publishes prolifically — it ships coordinated security releases roughly every month, so VulniPulse ingests GitLab's CVEs from the NVD CNA feed (cve@gitlab.com), a high-volume, authoritative source where each record names the affected CE/EE version range. Covers GitLab Community Edition and Enterprise Edition (self-managed), plus GitLab Runner and Pages — self-hosted DevOps platforms that are a repeated RCE / auth-bypass target, so a patch-now audience.

Latest GitLab advisories

Medium4.3GitLab

Medium [CVE-2026-10733] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that could have allowed an authenticated user to cause denial of service on the CI/CD Catalog page due to improper sanitization.

CVE-2026-10733
GitLab CE / EE
Jun 11, 2026
Medium5.6GitLab

Medium [CVE-2026-6899] GitLab: Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the…

Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate. Affected product named by the advisory: GitLab.

CVE-2026-6899
Unclassified
Jun 9, 2026
Medium4.3GitLab

Medium [CVE-2026-9807] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.11 before 18.11.4, and 19.0…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed a blocked Project Access Token to continue accessing private resources due to incorrect authorization enforcement.

CVE-2026-9807
GitLab CE / EE
May 28, 2026
Medium5.5GitLab

Medium [CVE-2026-9759] GitLab: ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service

ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-9759
Unclassified
May 27, 2026
Medium4.3GitLab

Medium [CVE-2026-8716] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended.

CVE-2026-8716
GitLab CE / EE
May 27, 2026
Medium5.3GitLab

Medium [CVE-2026-6713] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an unauthorized user to enumerate private projects due to incorrect authorization checks.

CVE-2026-6713
GitLab CE / EE
May 27, 2026
Medium5.4GitLab

Medium [CVE-2026-6515] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and 18.11…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed a user to use invalidated or incorrectly scoped credentials to access Virtual Registries under certain conditions.

CVE-2026-6515
GitLab CE / EE
Apr 22, 2026
Medium4.3GitLab

Medium [CVE-2026-5377] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that could have allowed an authenticated user to access titles of confidential or private issues in public projects due to improper access control in the issue description rendering process.

CVE-2026-5377
GitLab CE / EE
Apr 22, 2026
Medium6.5GitLab

Medium [CVE-2026-1660] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and 18.11…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to cause denial of service when importing issues due to improper input validation.

CVE-2026-1660
GitLab CE / EE
Apr 22, 2026
Medium6.5GitLab

Medium [CVE-2025-6016] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and 18.11…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service due to insufficient resource allocation limits when retrieving notes under certain conditions.

CVE-2025-6016
GitLab CE / EE
Apr 22, 2026
Medium6.5GitLab

Medium [CVE-2025-3922] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service by overwhelming system resources under certain conditions due to insufficient resource allocation limits in the GraphQL API.

CVE-2025-3922
GitLab CE / EE
Apr 22, 2026
Medium6.5GitLab

Medium [CVE-2025-0186] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service under certain conditions by exhausting server resources by making crafted requests to a discussions endpoint.

CVE-2025-0186
GitLab CE / EE
Apr 22, 2026
Medium5.4GitLab

Medium [CVE-2026-4332] GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before…

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization.

CVE-2026-4332
GitLab CE / EE
Apr 8, 2026
Medium4.3GitLab

Medium [CVE-2026-2619] GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before…

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization.

CVE-2026-2619
GitLab CE / EE
Apr 8, 2026
Medium4.3GitLab

Medium [CVE-2026-2104] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to access confidential issues assigned to other users via CSV export due to insufficient authorization checks.

CVE-2026-2104
GitLab CE / EE
Apr 8, 2026
Medium4.3GitLab

Medium [CVE-2026-1752] GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before…

GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with developer-role permissions to modify protected environment settings due to improper authorization checks in the API.

CVE-2026-1752
GitLab CE / EE
Apr 8, 2026
Medium5.7GitLab

Medium [CVE-2026-1516] GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10…

GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of users viewing the report via specially crafted content.

CVE-2026-1516
GitLab CE / EE
Apr 8, 2026
Medium6.5GitLab

Medium [CVE-2026-1101] GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before…

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to cause denial of service to the GitLab instance due to improper input validation in GraphQL queries.

CVE-2026-1101
GitLab CE / EE
Apr 8, 2026
Medium4.3GitLab

Medium [CVE-2025-9484] GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before…

GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user to have access to other users' email addresses via certain GraphQL queries.

CVE-2025-9484
GitLab CE / EE
Apr 8, 2026
Medium5.4GitLab

Medium [CVE-2026-2973] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to execute arbitrary JavaScript in a user's browser due to improper sanitization of entity-encoded content in Mermaid diagrams.

CVE-2026-2973
GitLab CE / EE
Mar 25, 2026

← All vendors