VYPR

GitLab

by GitLab Inc.

Source repositories

CVEs (1,455)

  • CVE-2025-5121HigJun 20, 2025
    risk 0.56cvss 8.5epss 0.12

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.

  • CVE-2022-0244HigJan 18, 2022
    risk 0.56cvss 8.6epss 0.02

    An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.

  • CVE-2026-79708HigSep 16, 2026
    risk 0.55cvss 8.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to execute a policy test pipeline on projects…

  • CVE-2026-88765HigSep 15, 2026
    risk 0.55cvss 8.5epss 0.01

    GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a specially crafted Git project export to…

  • CVE-2026-10053HigAug 23, 2026
    risk 0.55cvss 8.5epss 0.01

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability…

  • CVE-2026-15423HigAug 12, 2026
    risk 0.55cvss 8.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute CI/CD pipelines on a…

  • CVE-2026-5173HigApr 8, 2026
    risk 0.55cvss 8.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper…

  • CVE-2025-11702HigOct 29, 2025
    risk 0.55cvss 8.5epss 0.01

    GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker with specific permissions to hijack project runners from other projects.

  • CVE-2025-6454HigSep 12, 2025
    risk 0.55cvss 8.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to make unintended internal requests through proxy environments by injecting crafted sequences.

  • CVE-2024-9693HigNov 14, 2024
    risk 0.55cvss 8.5epss 0.01

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific…

  • CVE-2023-3399HigNov 6, 2023
    risk 0.55cvss 8.5epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD…

  • CVE-2022-2497HigAug 5, 2022
    risk 0.55cvss 8.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. A malicious developer could exfiltrate an integration's access token by modifying…

  • CVE-2021-22190HigApr 12, 2021
    risk 0.55cvss 8.5epss 0.02

    A path traversal vulnerability via the GitLab Workhorse in all versions of GitLab could result in the leakage of a JWT token

  • CVE-2018-19571HigJul 10, 2019
    risk 0.55cvss 7.7epss 0.28

    GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

  • CVE-2023-5009HigSep 19, 2023
    risk 0.54cvss 8.2epss 0.10

    An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of…

  • CVE-2022-3265HigNov 9, 2022
    risk 0.54cvss 7.3epss 0.86

    A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed…

  • CVE-2020-13321HigSep 30, 2020
    risk 0.54cvss 8.3epss 0.01

    A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added.

  • CVE-2026-78252HigSep 16, 2026
    risk 0.53cvss 8.2epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user could have induced a targeted user to perform unintended state-changing HTTP requests…

  • CVE-2026-75871HigAug 27, 2026
    risk 0.53cvss 8.2epss 0.00

    GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect outbound model…

  • CVE-2026-4868HigMay 27, 2026
    risk 0.53cvss 8.2epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authenticated user to cause specific Duo AI workflows to run under another user's…

Page 7 of 73