Skip to content
VulniPulse

GitLab Security Advisories & CVEs

3 advisories tracked · GitLab (cve@gitlab.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor GitLab CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your GitLab device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in GitLab's recent advisories.

Official source

GitLab (cve@gitlab.com CNA) via NVD

GitLab is its own CVE Numbering Authority and publishes prolifically — it ships coordinated security releases roughly every month, so VulniPulse ingests GitLab's CVEs from the NVD CNA feed (cve@gitlab.com), a high-volume, authoritative source where each record names the affected CE/EE version range. Covers GitLab Community Edition and Enterprise Edition (self-managed), plus GitLab Runner and Pages — self-hosted DevOps platforms that are a repeated RCE / auth-bypass target, so a patch-now audience.

Latest GitLab advisories

Critical9.4GitLab

Critical [CVE-2026-19478] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

CVE-2026-19478
Unclassified
Aug 17, 2026
Critical10.0GitLab Exploited CISA KEV

Critical [CVE-2023-7028] Weak Password Recovery Mechanism for Forgotten Password in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVE-2023-7028
Unclassified
Jan 12, 2024
Critical10.0GitLab Exploited CISA KEV

Critical [CVE-2021-22205] issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

CVE-2021-22205
Unclassified
Apr 23, 2021

← All vendors