Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

GitLab — Vulnerabilities & Security Advisories 1012

All 1012 CVE vulnerabilities found in GitLab, with AI-generated Chinese analysis, references, and POCs.

This is a vulnerability aggregation page for the open-source DevOps platform GitLab, specifically tracking Common Weakness Enumeration (CWE) identified security flaws. The page collects a comprehensive list of known vulnerabilities affecting GitLab, encompassing critical issues such as cross-site scripting, injection flaws, and improper access control mechanisms. This dataset covers security advisories and disclosed weaknesses released from the platform's inception through the current date, ensuring a complete historical record of security incidents. By utilizing this resource, security professionals and administrators can effectively track vendor security advisories to monitor the current patch status and compliance posture. Users can also gain a deeper understanding of specific weakness classes by analyzing patterns in how GitLab has addressed different types of logical and architectural errors over time. Furthermore, this page allows for the lookup of a specific product's vulnerability history, enabling teams to assess long-term security trends and the frequency of similar defects across various versions. This consolidated view supports informed risk management decisions by providing clear visibility into past security incidents and their resolutions. The information presented is intended for technical analysis and operational planning, helping organizations prioritize remediation efforts based on the severity and prevalence of the documented weaknesses without bias or promotional content.

Vendor: GitLab

CVE IDTitleCVSSSeverityPublished
CVE-2025-6016 Allocation of Resources Without Limits or Throttling in GitLab CWE-770 6.5 Medium2026-04-22
CVE-2025-9957 Incorrect Authorization in GitLab CWE-863 2.7 Low2026-04-22
CVE-2026-1660 Allocation of Resources Without Limits or Throttling in GitLab CWE-770 6.5 Medium2026-04-22
CVE-2026-5262 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 8.0 High2026-04-22
CVE-2026-5377 Incorrect Authorization in GitLab CWE-863 4.3 Medium2026-04-22
CVE-2026-5816 Improper Resolution of Path Equivalence in GitLab CWE-41 8.0 High2026-04-22
CVE-2026-6515 Insufficient Session Expiration in GitLab CWE-613 5.4 Medium2026-04-22
CVE-2025-9484 Missing Authorization in GitLab CWE-862 4.3 Medium2026-04-08
CVE-2025-12664 Improper Validation of Specified Quantity in Input in GitLab CWE-1284 7.5 High2026-04-08
CVE-2026-1092 Improper Validation of Specified Quantity in Input in GitLab CWE-1284 7.5 High2026-04-08
CVE-2026-1101 Improper Validation of Specified Quantity in Input in GitLab CWE-1284 6.5 Medium2026-04-08
CVE-2026-1516 Improper Control of Generation of Code ('Code Injection') in GitLab CWE-94 5.7 Medium2026-04-08
CVE-2026-1752 Incorrect Authorization in GitLab CWE-863 4.3 Medium2026-04-08
CVE-2026-2104 Authorization Bypass Through User-Controlled Key in GitLab CWE-639 4.3 Medium2026-04-08
CVE-2026-2619 Incorrect Authorization in GitLab CWE-863 4.3 Medium2026-04-08
CVE-2026-4332 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 5.4 Medium2026-04-08
CVE-2026-4916 Missing Authorization in GitLab CWE-862 2.7 Low2026-04-08
CVE-2026-5173 Exposed Dangerous Method or Function in GitLab CWE-749 8.5 High2026-04-08
CVE-2026-2370 Improper Handling of Parameters in GitLab CWE-233 8.1 High2026-03-29
CVE-2025-13078 Improper Validation of Specified Quantity in Input in GitLab CWE-1284 6.5 Medium2026-03-25
CVE-2025-13436 Allocation of Resources Without Limits or Throttling in GitLab CWE-770 6.5 Medium2026-03-25
CVE-2025-14595 Missing Authorization in GitLab CWE-862 4.3 Medium2026-03-25
CVE-2026-1724 Missing Authentication for Critical Function in GitLab CWE-306 6.8 Medium2026-03-25
CVE-2026-2745 Authentication Bypass Using an Alternate Path or Channel in GitLab CWE-288 6.8 Medium2026-03-25
CVE-2026-2726 Incorrect Authorization in GitLab CWE-863 4.3 Medium2026-03-25
CVE-2026-2973 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab CWE-79 5.4 Medium2026-03-25
CVE-2026-2995 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab CWE-80 7.7 High2026-03-25
CVE-2026-3857 Cross-Site Request Forgery (CSRF) in GitLab CWE-352 8.1 High2026-03-25
CVE-2026-3988 Inefficient Algorithmic Complexity in GitLab CWE-407 7.5 High2026-03-25
CVE-2026-4363 Incorrect Authorization in GitLab CWE-863 3.7 Low2026-03-25

All 1012 known CVE vulnerabilities affecting GitLab with full Chinese analysis, references, and POCs where available.