VYPR

apk package

chainguard/gitlab-toolbox-ce-fips-19.0

pkg:apk/chainguard/gitlab-toolbox-ce-fips-19.0

Vulnerabilities (11)

  • CVE-2026-9694LowJun 11, 2026
    affected < 19.0.2-r0fixed 19.0.2-r0

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, could have allowed an unauthenticated user to impersonate the GitLab Support Bot and inject arbitrary conten

  • CVE-2026-9204MedJun 11, 2026
    affected < 19.0.2-r0fixed 19.0.2-r0

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to read arbitrary files from the Gitaly server and access internal

  • CVE-2026-8589HigJun 11, 2026
    affected < 19.0.2-r0fixed 19.0.2-r0

    GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to add unauthorized email addresses to a targeted user's account due

  • CVE-2026-7250HigJun 11, 2026
    affected < 19.0.2-r0fixed 19.0.2-r0

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in th

  • CVE-2026-6976LowJun 11, 2026
    affected < 19.0.2-r0fixed 19.0.2-r0

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to hide changes from merge request d

  • CVE-2026-6552HigJun 11, 2026
    affected < 19.0.2-r0fixed 19.0.2-r0

    GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with group Owner role to take over another group member's GitLab accoun

  • CVE-2026-6277MedJun 11, 2026
    affected < 19.0.2-r0fixed 19.0.2-r0

    GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with Security Manager-role permissions to manage project security confi

  • CVE-2026-8716MedMay 27, 2026
    affected < 19.0.2-r0fixed 19.0.2-r0

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended.

  • CVE-2026-6713MedMay 27, 2026
    affected < 19.0.2-r0fixed 19.0.2-r0

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an unauthorized user to enumerate private projects due to incorrect authorization checks.

  • CVE-2026-1402MedMay 27, 2026
    affected < 19.0.2-r0fixed 19.0.2-r0

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to cause denial of service due to insufficient validation.

  • CVE-2026-27459Mar 17, 2026
    affected < 19.0.2-r1fixed 19.0.2-r1

    pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Sta