VYPR

GitLab

by GitLab Inc.

Source repositories

CVEs (1,433)

  • CVE-2021-32823LowJun 24, 2021
    risk 0.17cvss 3.7epss 0.02

    In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit. In…

  • CVE-2021-22218LowJun 8, 2021
    risk 0.17cvss 2.6epss 0.00

    All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all versions starting from 13.12 before 13.12.2 were affected by an issue in the handling of x509 certificates that could be used to spoof author of signed…

  • CVE-2019-7176LowSep 9, 2019
    risk 0.17cvss 3.7epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they…

  • CVE-2024-5528LowFeb 5, 2025
    risk 0.16cvss 3.5epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.

  • CVE-2024-6446LowSep 12, 2024
    risk 0.16cvss 3.5epss 0.00

    An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.3 prior to 17.3.2. A crafted URL could be used to trick a victim to trust an attacker controlled application.

  • CVE-2022-1111LowApr 4, 2022
    risk 0.16cvss 2.4epss 0.01

    A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

  • CVE-2022-0093LowJan 18, 2022
    risk 0.16cvss 3.5epss 0.01

    An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

  • CVE-2021-22202LowApr 2, 2021
    risk 0.16cvss 2.4epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all previous versions. If the victim is an admin, it was possible to issue a CSRF in System hooks through the API.

  • CVE-2025-12697LowMar 11, 2026
    risk 0.14cvss 2.2epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API credentials under certain conditions.

  • CVE-2022-2534LowAug 5, 2022
    risk 0.14cvss 2.2epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was returning contributor emails due to improper data handling in the Datadog…

  • CVE-2021-39879LowOct 4, 2021
    risk 0.14cvss 2.2epss 0.00

    Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

  • CVE-2025-13611LowNov 26, 2025
    risk 0.13cvss 2.0epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific conditions.

  • CVE-2023-3511LowDec 15, 2023
    risk 0.13cvss 2.0epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private…

  • CVE-2022-1426LowMay 11, 2022
    risk 0.13cvss 2.0epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of…

  • CVE-2021-39900LowOct 4, 2021
    risk 0.13cvss 2.0epss 0.01

    Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.

  • CVE-2021-39911LowNov 5, 2021
    risk 0.11cvss 1.7epss 0.01

    An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data…

  • CVE-2013-4490May 13, 2014
    risk 0.06cvss epss 0.42

    The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.

  • CVE-2013-7316Jan 24, 2014
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML file, as demonstrated by README.html.

  • CVE-2026-6336MedJul 29, 2026
    risk 0.00cvss 5.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthorized user to view project import source information due to a missing…

  • CVE-2026-6267HigJul 29, 2026
    risk 0.00cvss 8.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to…