Skip to content
VulniPulse

GitLab Security Advisories & CVEs

136 advisories tracked · GitLab (cve@gitlab.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor GitLab CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your GitLab device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in GitLab's recent advisories.

Official source

GitLab (cve@gitlab.com CNA) via NVD

GitLab is its own CVE Numbering Authority and publishes prolifically — it ships coordinated security releases roughly every month, so VulniPulse ingests GitLab's CVEs from the NVD CNA feed (cve@gitlab.com), a high-volume, authoritative source where each record names the affected CE/EE version range. Covers GitLab Community Edition and Enterprise Edition (self-managed), plus GitLab Runner and Pages — self-hosted DevOps platforms that are a repeated RCE / auth-bypass target, so a patch-now audience.

Latest GitLab advisories

Low0.0GitLab

Low [CVE-2026-12635] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to make requests to internal network resources through mirror synchronization due to improper URL validation

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to make requests to internal network resources through mirror synchronization due to improper URL validation.

CVE-2026-12635
GitLab CE / EE
Jun 25, 2026
Low3.8GitLab

Low [CVE-2026-0934] GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with custom role permissions to view, create, or delete protected environment configurations despite CI/CD visibility being disabled for the project

GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with custom role permissions to view, create, or delete protected environment configurations despite CI/CD visibility being disabled for the project.

CVE-2026-0934
GitLab CE / EE
Jun 25, 2026
Medium5.5GitLab

Medium [CVE-2026-11968] GitLab: Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit

Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit Affected product named by the advisory: GitLab.

CVE-2026-11968
Unclassified
Jun 24, 2026
High7.3GitLab

High [CVE-2026-8589] GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0…

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to add unauthorized email addresses to a targeted user's account due to improper sanitization of user-supplied input in certain group setting fields.

CVE-2026-8589
GitLab CE / EE
Jun 11, 2026
High7.5GitLab

High [CVE-2026-7250] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsing middleware.

CVE-2026-7250
GitLab CE / EE
Jun 11, 2026
High8.7GitLab

High [CVE-2026-6552] GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0…

GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with group Owner role to take over another group member's GitLab account due to improper authorization in the Group SAML identity management functionality.

CVE-2026-6552
GitLab CE / EE
Jun 11, 2026
High8.7GitLab

High [CVE-2026-10087] GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0…

GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code on behalf of a targeted user due to improper input sanitization in the Analytics Dashboard.

CVE-2026-10087
GitLab CE / EE
Jun 11, 2026
Medium5.3GitLab

Medium [CVE-2026-9204] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to read arbitrary files from the Gitaly server and access internal network resources during repository import, due to insufficient validation of secondary URLs.

CVE-2026-9204
GitLab CE / EE
Jun 11, 2026
Medium4.3GitLab

Medium [CVE-2026-6277] GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 19.0…

GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with Security Manager-role permissions to manage project security configuration even when the relevant feature was in a disabled state, due to incorrect authorization enforcement.

CVE-2026-6277
GitLab CE / EE
Jun 11, 2026
Medium5.4GitLab

Medium [CVE-2026-6269] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to modify hidden merge requests due to incorrect authorization enforcements.

CVE-2026-6269
GitLab CE / EE
Jun 11, 2026
Medium6.5GitLab

Medium [CVE-2026-1500] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to cause denial of service due to uncontrolled resource consumption when processing a specially crafted file upload.

CVE-2026-1500
GitLab CE / EE
Jun 11, 2026
Medium4.3GitLab

Medium [CVE-2026-10733] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that could have allowed an authenticated user to cause denial of service on the CI/CD Catalog page due to improper sanitization.

CVE-2026-10733
GitLab CE / EE
Jun 11, 2026
Low2.6GitLab

Low [CVE-2026-9694] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, could have allowed an unauthenticated user to impersonate the GitLab Support Bot and inject arbitrary content via a specially crafted Service Desk email reply due to improper neutralization in email template processing

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, could have allowed an unauthenticated user to impersonate the GitLab Support Bot and inject arbitrary content via a specially crafted Service Desk email reply due to improper neutralization in email template processing.

CVE-2026-9694
GitLab CE / EE
Jun 11, 2026
Low3.7GitLab

Low [CVE-2026-6976] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to hide changes from merge request diff views due to improper input handling of file names.

CVE-2026-6976
GitLab CE / EE
Jun 11, 2026
Low3.1GitLab

Low [CVE-2026-3553] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to access confidential issue details due to incorrect authorization checks.

CVE-2026-3553
GitLab CE / EE
Jun 11, 2026
High7.3GitLab

High [CVE-2026-9758] GitLab: Improper comparison with the certificates trusted list in S2OPC

Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered trusted Affected product named by the advisory: GitLab.

CVE-2026-9758
Unclassified
Jun 10, 2026
Medium5.6GitLab

Medium [CVE-2026-6899] GitLab: Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the…

Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It might allow connection between an OPC UA client and server using a revoked certificate. Affected product named by the advisory: GitLab.

CVE-2026-6899
Unclassified
Jun 9, 2026
Medium4.3GitLab

Medium [CVE-2026-9807] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.11 before 18.11.4, and 19.0…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed a blocked Project Access Token to continue accessing private resources due to incorrect authorization enforcement.

CVE-2026-9807
GitLab CE / EE
May 28, 2026
Medium5.5GitLab

Medium [CVE-2026-9759] GitLab: ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service

ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-9759
Unclassified
May 27, 2026
Medium4.3GitLab

Medium [CVE-2026-8716] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended.

CVE-2026-8716
GitLab CE / EE
May 27, 2026

← All vendors