Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

GitLab — Vulnerabilities & Security Advisories 1083

All 1083 CVE vulnerabilities found in GitLab, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting GitLab, organized by vendor, product, and Common Weakness Enumeration (CWE) classification tags. It collects a comprehensive history of disclosed issues, spanning the full period during which GitLab has been commercially available, including both open-source and self-managed enterprise editions. Readers can use this resource to track the vendor's published security advisories, understand the frequency and severity trends of specific weakness classes, and review the complete vulnerability timeline for the GitLab platform. The data presented helps security teams identify recurring patterns, such as memory corruption or authentication flaws, without requiring individual lookups of separate CVE records. By consolidating these records, the page provides a structured overview of the product’s security posture, facilitating risk assessment and comparative analysis against other systems.

Vendor: GitLab

CVE ID Title CVSS Severity Published
CVE-2026-7250 Allocation of Resources Without Limits or Throttling in GitLab CWE-770 7.5 High 2026-06-11
CVE-2026-8589 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 7.3 High 2026-06-11
CVE-2026-9204 Server-Side Request Forgery (SSRF) in GitLab CWE-918 5.3 Medium 2026-06-11
CVE-2026-9694 Improper Neutralization of Substitution Characters in GitLab CWE-153 2.6 Low 2026-06-11
CVE-2026-10087 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 8.7 High 2026-06-11
CVE-2026-10733 Improper Restriction of Rendered UI Layers or Frames in GitLab CWE-1021 4.3 Medium 2026-06-11
CVE-2026-9807 Incorrect Authorization in GitLab CWE-863 4.3 Medium 2026-05-28
CVE-2026-1402 Allocation of Resources Without Limits or Throttling in GitLab CWE-770 6.5 Medium 2026-05-27
CVE-2026-2601 Missing Authorization in GitLab CWE-862 4.3 Medium 2026-05-27
CVE-2026-4868 Authorization Bypass Through User-Controlled Key in GitLab CWE-639 8.2 High 2026-05-27
CVE-2026-5296 Missing Authorization in GitLab CWE-862 4.3 Medium 2026-05-27
CVE-2026-6713 Incorrect Authorization in GitLab CWE-863 5.3 Medium 2026-05-27
CVE-2026-8716 Use of Incorrectly-Resolved Name or Reference in GitLab CWE-706 4.3 Medium 2026-05-27
CVE-2025-12669 Improper Control of Generation of Code ('Code Injection') in GitLab CWE-94 5.4 Medium 2026-05-14
CVE-2025-13874 Authorization Bypass Through User-Controlled Key in GitLab CWE-639 4.3 Medium 2026-05-14
CVE-2025-14869 Improper Validation of Specified Quantity in Input in GitLab CWE-1284 7.5 High 2026-05-14
CVE-2025-14870 Allocation of Resources Without Limits or Throttling in GitLab CWE-770 7.5 High 2026-05-14
CVE-2026-1184 Deserialization of Untrusted Data in GitLab CWE-502 6.5 Medium 2026-05-14
CVE-2026-1322 Business Logic Errors in GitLab CWE-840 6.8 Medium 2026-05-14
CVE-2026-1338 Authorization Bypass Through User-Controlled Key in GitLab CWE-639 4.3 Medium 2026-05-14
CVE-2026-1659 Allocation of Resources Without Limits or Throttling in GitLab CWE-770 7.5 High 2026-05-14
CVE-2026-2900 Missing Authorization in GitLab CWE-862 2.7 Low 2026-05-14
CVE-2026-3073 Authorization Bypass Through User-Controlled Key in GitLab CWE-639 4.3 Medium 2026-05-14
CVE-2026-3074 Authorization Bypass Through User-Controlled Key in GitLab CWE-639 4.3 Medium 2026-05-14
CVE-2026-3160 Unintended Proxy or Intermediary ('Confused Deputy') in GitLab CWE-441 5.8 Medium 2026-05-14
CVE-2026-3607 Access Control Check Implemented After Asset is Accessed in GitLab CWE-1280 4.3 Medium 2026-05-14
CVE-2026-4524 Authentication Bypass Using an Alternate Path or Channel in GitLab CWE-288 6.5 Medium 2026-05-14
CVE-2026-4527 Cross-Site Request Forgery (CSRF) in GitLab CWE-352 6.5 Medium 2026-05-14
CVE-2026-6063 Authorization Bypass Through User-Controlled Key in GitLab CWE-639 4.3 Medium 2026-05-14
CVE-2026-6073 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 8.7 High 2026-05-14

All 1083 known CVE vulnerabilities affecting GitLab with full Chinese analysis, references, and POCs where available.