Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

GitLab — Vulnerabilities & Security Advisories 1083

All 1083 CVE vulnerabilities found in GitLab, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting GitLab, organized by vendor, product, and Common Weakness Enumeration (CWE) classification tags. It collects a comprehensive history of disclosed issues, spanning the full period during which GitLab has been commercially available, including both open-source and self-managed enterprise editions. Readers can use this resource to track the vendor's published security advisories, understand the frequency and severity trends of specific weakness classes, and review the complete vulnerability timeline for the GitLab platform. The data presented helps security teams identify recurring patterns, such as memory corruption or authentication flaws, without requiring individual lookups of separate CVE records. By consolidating these records, the page provides a structured overview of the product’s security posture, facilitating risk assessment and comparative analysis against other systems.

Vendor: GitLab

CVE ID Title CVSS Severity Published
CVE-2026-1403 Allocation of Resources Without Limits or Throttling in GitLab CWE-770 6.5 Medium 2026-10-07
CVE-2026-4523 Missing Authorization in GitLab CWE-862 3.7 Low 2026-09-29
CVE-2026-8937 Missing Authorization in GitLab CWE-862 4.3 Medium 2026-09-29
CVE-2026-10518 Incorrect Authorization in GitLab CWE-863 4.3 Medium 2026-09-29
CVE-2026-84739 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 8.7 High 2026-09-29
CVE-2026-89078 Double Free in GitLab CWE-415 9.9 Critical 2026-09-23
CVE-2026-92530 Use of Less Trusted Source in GitLab CWE-348 4.3 Medium 2026-09-23
CVE-2026-92470 Missing Authorization in GitLab CWE-862 7.7 High 2026-09-23
CVE-2026-92529 Incorrect Authorization in GitLab CWE-863 4.3 Medium 2026-09-23
CVE-2026-92874 Incorrect Authorization in GitLab CWE-863 5.4 Medium 2026-09-23
CVE-2026-92628 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitLab CWE-362 3.1 Low 2026-09-23
CVE-2026-93577 Integer Overflow or Wraparound in GitLab CWE-190 9.9 Critical 2026-09-23
CVE-2026-86341 Access Control Check Implemented After Asset is Accessed in GitLab CWE-1280 4.4 Medium 2026-09-16
CVE-2024-11222 Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab CWE-367 6.4 Medium 2026-09-16
CVE-2025-14871 Allocation of Resources Without Limits or Throttling in GitLab CWE-770 7.5 High 2026-09-16
CVE-2026-1168 Allocation of Resources Without Limits or Throttling in GitLab CWE-770 7.5 High 2026-09-16
CVE-2026-3855 Improper Control of Resource Identifiers ('Resource Injection') in GitLab CWE-99 3.1 Low 2026-09-16
CVE-2026-7514 Missing Authorization in GitLab CWE-862 4.3 Medium 2026-09-16
CVE-2026-8030 Missing Authorization in GitLab CWE-862 4.3 Medium 2026-09-16
CVE-2026-16794 Missing Authorization in GitLab CWE-862 4.3 Medium 2026-09-16
CVE-2026-19619 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 4.7 Medium 2026-09-16
CVE-2026-78252 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 8.2 High 2026-09-16
CVE-2026-79708 Incorrect Authorization in GitLab CWE-863 8.5 High 2026-09-16
CVE-2026-12910 Missing Authentication for Critical Function in GitLab CWE-306 5.4 Medium 2026-09-15
CVE-2026-13210 Incorrect Authorization in GitLab CWE-863 7.7 High 2026-09-15
CVE-2026-82837 Insertion of Sensitive Information Into Sent Data in GitLab CWE-201 5.3 Medium 2026-09-15
CVE-2026-88765 Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab CWE-77 8.5 High 2026-09-15
CVE-2026-85706 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab CWE-22 10.0 Critical 2026-09-12
CVE-2026-87719 Deserialization of Untrusted Data in GitLab CWE-502 9.9 Critical 2026-09-12
CVE-2026-4398 Authorization Bypass Through User-Controlled Key in GitLab CWE-639 5.4 Medium 2026-08-27

All 1083 known CVE vulnerabilities affecting GitLab with full Chinese analysis, references, and POCs where available.