VYPR

Bitnami package

gitlab

pkg:bitnami/gitlab

Vulnerabilities (1,054)

  • CVE-2026-8280MedMay 14, 2026
    affected >= 8.3.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to cause denial of service through excessive memory consumption due to improper input validat

  • CVE-2026-8144MedMay 14, 2026
    affected >= 15.1.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with project membership to enumerate private group members due to missing authorization chec

  • CVE-2026-7481HigMay 14, 2026
    affected >= 16.4.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to execute arbitrary JavaScript in other users' browsers due to

  • CVE-2026-7471LowMay 14, 2026
    affected >= 18.8.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with control of a virtual registry upstream to make requests to internal hosts due to improper

  • CVE-2026-7377HigMay 14, 2026
    affected >= 18.7.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other

  • CVE-2026-6883LowMay 14, 2026
    affected >= 15.7.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to bypass merge request approval requirements due to improper cleanup of orphaned policy record

  • CVE-2026-6335MedMay 14, 2026
    affected >= 18.11.0, < 18.11.3fixed 18.11.3

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.3 that under certain conditions could have allowed an authenticated user to execute arbitrary code in another user's browser session due to improper sanitization.

  • CVE-2026-6073HigMay 14, 2026
    affected >= 18.7.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to execute arbitrary JavaScript in other users' browsers due to improper input sanitization.

  • CVE-2026-6063MedMay 14, 2026
    affected >= 11.10.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that under certain conditions could have allowed an authenticated user with developer-role permissions to remove code owner approval rules f

  • CVE-2026-4527MedMay 14, 2026
    affected >= 11.10.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to create unauthorized Jira subscriptions for a targeted user's namespace via a specially

  • CVE-2026-4524MedMay 14, 2026
    affected >= 18.9.1, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to access confidential issue content in public projects without proper authorization due t

  • CVE-2026-3607MedMay 14, 2026
    affected >= 18.3.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to bypass package protection rules due to improper access co

  • CVE-2026-3160MedMay 14, 2026
    affected >= 13.7.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to view Jira issues outside the configured project scope due to an integration filter functi

  • CVE-2026-3074MedMay 14, 2026
    affected >= 16.7.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to download private debugging symbols from inaccessible projects due to improper access co

  • CVE-2026-3073MedMay 14, 2026
    affected >= 17.6.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to bypass PyPI package protection rules and upload restricte

  • CVE-2026-2900LowMay 14, 2026
    affected >= 16.10.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that when instance-level approval rule editing prevention was enabled, could have allowed an authenticated user with Maintainer permissions

  • CVE-2026-1659HigMay 14, 2026
    affected >= 9.0.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted requests due to insufficient input

  • CVE-2026-1338MedMay 14, 2026
    affected >= 17.10.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to delete protected container registry tags due to improper

  • CVE-2026-1322MedMay 14, 2026
    affected >= 16.0.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with a read_api scoped OAuth application to create issues and add comments to issues in priv

  • CVE-2026-1184MedMay 14, 2026
    affected >= 11.9.0, < 18.9.7fixed 18.9.7

    GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by uploading a specially crafted file due to improper validation.

Page 1 of 53