Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

GitLab — Vulnerabilities & Security Advisories 1047

All 1047 CVE vulnerabilities found in GitLab, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for GitLab, a popular web-based DevOps lifecycle tool, categorized by weakness type and relevant security tags. It collects data on critical infrastructure flaws, application-level bugs, and configuration errors spanning from the initial release up to the most recent advisories. Visitors can track GitLab’s security update history, understand specific weakness classes affecting the platform, and look up the product's vulnerability timeline to assess risk exposure over time. The content is structured to help security professionals, developers, and system administrators quickly identify affected versions and understand the nature of disclosed issues without navigating fragmented sources. By centralizing this information, the page supports informed decision-making regarding patching schedules and mitigation strategies. Data includes publicly disclosed Common Vulnerabilities and Exposures (CVE) identifiers, severity ratings, and references to official GitLab security announcements. The scope covers server-side processing flaws, authentication bypasses, permission escalation issues, and data exposure risks. Users can filter results by version or vulnerability type to isolate relevant findings for their specific environment. This resource aims to provide a comprehensive overview of GitLab’s security posture over time, facilitating better risk management and compliance monitoring. All information is sourced from official vendor disclosures and recognized vulnerability databases to ensure accuracy and reliability. Regular updates are performed to reflect the latest security landscape for the GitLab platform.

Vendor: GitLab

CVE ID Title CVSS Severity Published
CVE-2026-10053 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab CWE-22 8.5 High 2026-08-23
CVE-2026-19650 Cross-Site Request Forgery (CSRF) in GitLab CWE-352 7.1 High 2026-08-17
CVE-2026-19478 Improper Control of Generation of Code ('Code Injection') in GitLab CWE-94 9.4 Critical 2026-08-17
CVE-2025-9486 Incorrect Privilege Assignment in GitLab CWE-266 3.3 Low 2026-08-12
CVE-2026-4879 Missing Authorization in GitLab CWE-862 4.3 Medium 2026-08-12
CVE-2026-6821 Missing Authorization in GitLab CWE-862 4.3 Medium 2026-08-12
CVE-2026-15217 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 8.7 High 2026-08-12
CVE-2026-15216 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 8.7 High 2026-08-12
CVE-2026-16494 Missing Authorization in GitLab CWE-862 7.1 High 2026-08-12
CVE-2026-18433 Incorrect Authorization in GitLab CWE-863 4.3 Medium 2026-08-12
CVE-2026-19228 Authorization Bypass Through User-Controlled Key in GitLab CWE-639 8.5 High 2026-08-12
CVE-2026-7427 Allocation of Resources Without Limits or Throttling in GitLab CWE-770 5.3 Medium 2026-08-12
CVE-2026-8667 Incorrect Authorization in GitLab CWE-863 4.3 Medium 2026-08-12
CVE-2026-15423 Incorrect Authorization in GitLab CWE-863 8.5 High 2026-08-12
CVE-2026-16627 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 7.7 High 2026-08-12
CVE-2026-18244 Missing Authorization in GitLab CWE-862 4.3 Medium 2026-08-12
CVE-2025-14562 Incorrect Authorization in GitLab CWE-863 3.1 Low 2026-07-29
CVE-2026-3093 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 4.7 Medium 2026-07-29
CVE-2026-4672 Missing Authorization in GitLab CWE-862 4.3 Medium 2026-07-29
CVE-2026-6267 Insertion of Sensitive Information Into Sent Data in GitLab CWE-201 8.5 High 2026-07-29
CVE-2026-6336 Incorrect Authorization in GitLab CWE-863 5.3 Medium 2026-07-29
CVE-2026-12436 Improperly Controlled Modification of Dynamically-Determined Object Attributes in GitLab CWE-915 8.4 High 2026-07-29
CVE-2026-13113 Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab CWE-367 6.5 Medium 2026-07-29
CVE-2026-14341 Missing Authorization in GitLab CWE-862 4.9 Medium 2026-07-29
CVE-2026-14351 Exposure of Sensitive Information Through Metadata in GitLab CWE-1230 4.3 Medium 2026-07-29
CVE-2026-15077 Improper Neutralization of Input Used for LLM Prompting in GitLab CWE-1427 4.3 Medium 2026-07-29
CVE-2026-15831 Generation of Incorrect Security Tokens in GitLab CWE-1270 4.3 Medium 2026-07-29
CVE-2026-15975 Allocation of Resources Without Limits or Throttling in GitLab CWE-770 7.5 High 2026-07-29
CVE-2026-16553 Insufficiently Protected Credentials in GitLab CWE-522 5.4 Medium 2026-07-29
CVE-2025-12506 Use of Incorrectly-Resolved Name or Reference in GitLab CWE-706 3.5 Low 2026-07-08

All 1047 known CVE vulnerabilities affecting GitLab with full Chinese analysis, references, and POCs where available.