Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

GitLab — Vulnerabilities & Security Advisories 1012

All 1012 CVE vulnerabilities found in GitLab, with AI-generated Chinese analysis, references, and POCs.

This is a vulnerability aggregation page for the open-source DevOps platform GitLab, specifically tracking Common Weakness Enumeration (CWE) identified security flaws. The page collects a comprehensive list of known vulnerabilities affecting GitLab, encompassing critical issues such as cross-site scripting, injection flaws, and improper access control mechanisms. This dataset covers security advisories and disclosed weaknesses released from the platform's inception through the current date, ensuring a complete historical record of security incidents. By utilizing this resource, security professionals and administrators can effectively track vendor security advisories to monitor the current patch status and compliance posture. Users can also gain a deeper understanding of specific weakness classes by analyzing patterns in how GitLab has addressed different types of logical and architectural errors over time. Furthermore, this page allows for the lookup of a specific product's vulnerability history, enabling teams to assess long-term security trends and the frequency of similar defects across various versions. This consolidated view supports informed risk management decisions by providing clear visibility into past security incidents and their resolutions. The information presented is intended for technical analysis and operational planning, helping organizations prioritize remediation efforts based on the severity and prevalence of the documented weaknesses without bias or promotional content.

Vendor: GitLab

CVE IDTitleCVSSSeverityPublished
CVE-2026-10086 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 8.7 High2026-06-25
CVE-2026-0934 Incorrect Authorization in GitLab CWE-863 3.8 Low2026-06-25
CVE-2026-1606 Improper Control of Generation of Code ('Code Injection') in GitLab CWE-94 4.3 Medium2026-06-25
CVE-2026-2238 Missing Authorization in GitLab CWE-862 5.3 Medium2026-06-25
CVE-2026-3176 Missing Authorization in GitLab CWE-862 3.1 Low2026-06-25
CVE-2026-5309 Authorization Bypass Through User-Controlled Key in GitLab CWE-639 5.4 Medium2026-06-25
CVE-2026-5796 Incorrect Authorization in GitLab CWE-863 4.3 Medium2026-06-25
CVE-2026-5952 Incorrect Authorization in GitLab CWE-863 4.3 Medium2026-06-25
CVE-2026-8330 Insertion of Sensitive Information into Log File in GitLab CWE-532 4.4 Medium2026-06-25
CVE-2026-10712 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 8.0 High2026-06-25
CVE-2026-11379 Incorrect Authorization in GitLab CWE-863 5.3 Medium2026-06-25
CVE-2026-12053 Insertion of Sensitive Information into Log File in GitLab CWE-532 8.6 High2026-06-25
CVE-2026-12635 Reliance on Reverse DNS Resolution for a Security-Critical Action in GitLab CWE-350--2026-06-25
CVE-2026-1500 Allocation of Resources Without Limits or Throttling in GitLab CWE-770 6.5 Medium2026-06-11
CVE-2026-3553 Incorrect Authorization in GitLab CWE-863 3.1 Low2026-06-11
CVE-2026-6269 Incorrect Authorization in GitLab CWE-863 5.4 Medium2026-06-11
CVE-2026-6277 Incorrect Authorization in GitLab CWE-863 4.3 Medium2026-06-11
CVE-2026-6552 Authorization Bypass Through User-Controlled Key in GitLab CWE-639 8.7 High2026-06-11
CVE-2026-6976 Authorization Bypass Through User-Controlled Key in GitLab CWE-639 3.7 Low2026-06-11
CVE-2026-7250 Allocation of Resources Without Limits or Throttling in GitLab CWE-770 7.5 High2026-06-11
CVE-2026-8589 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 7.3 High2026-06-11
CVE-2026-9204 Server-Side Request Forgery (SSRF) in GitLab CWE-918 5.3 Medium2026-06-11
CVE-2026-9694 Improper Neutralization of Substitution Characters in GitLab CWE-153 2.6 Low2026-06-11
CVE-2026-10087 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 8.7 High2026-06-11
CVE-2026-10733 Improper Restriction of Rendered UI Layers or Frames in GitLab CWE-1021 4.3 Medium2026-06-11
CVE-2026-9807 Incorrect Authorization in GitLab CWE-863 4.3 Medium2026-05-28
CVE-2026-1402 Allocation of Resources Without Limits or Throttling in GitLab CWE-770 6.5 Medium2026-05-27
CVE-2026-2601 Missing Authorization in GitLab CWE-862 4.3 Medium2026-05-27
CVE-2026-4868 Authorization Bypass Through User-Controlled Key in GitLab CWE-639 8.2 High2026-05-27
CVE-2026-5296 Missing Authorization in GitLab CWE-862 4.3 Medium2026-05-27

All 1012 known CVE vulnerabilities affecting GitLab with full Chinese analysis, references, and POCs where available.