Gitlab Ce vulnerabilities
572 known vulnerabilities affecting gitlab/gitlab_ce.
Total CVEs
572
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL18HIGH128MEDIUM342LOW84
Vulnerabilities
Page 1 of 29
CVE-2026-5173HIGHCVSS 8.52026-04-08
CVE-2026-5173 [HIGH] CWE-749 CVE-2026-5173: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that cou
CVE-2026-5173: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control.
gitlab
CVE-2025-12664HIGHCVSS 7.52026-04-08
CVE-2025-12664 [HIGH] CWE-1284 CVE-2025-12664: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could
CVE-2025-12664: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.
gitlab
CVE-2026-1092HIGHCVSS 7.52026-04-08
CVE-2026-1092 [HIGH] CWE-1284 CVE-2026-1092: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that coul
CVE-2026-1092: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service due to improper input validation of JSON payloads.
gitlab
CVE-2026-2104MEDIUMCVSS 4.32026-04-08
CVE-2026-2104 [MEDIUM] CWE-639 CVE-2026-2104: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could
CVE-2026-2104: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to access confidential issues assigned to other users via CSV export due to insufficient authorization
gitlab
CVE-2026-4916LOWCVSS 2.72026-04-08
CVE-2026-4916 [LOW] CWE-862 CVE-2026-4916: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could
CVE-2026-4916: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authoriz
gitlab
CVE-2026-2370HIGHCVSS 8.12026-03-30
CVE-2026-2370 [HIGH] CWE-233 CVE-2026-2370: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting
CVE-2026-2370: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with minimal workspace permissions to obtain installation credential
gitlab
CVE-2026-3988HIGHCVSS 7.52026-03-25
CVE-2026-3988 [HIGH] CWE-407 CVE-2026-3988: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could
CVE-2026-3988: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to cause a denial of service by making the GitLab instance unresponsive due to improper input validati
gitlab
CVE-2026-3857HIGHCVSS 8.12026-03-25
CVE-2026-3857 [HIGH] CWE-352 CVE-2026-3857: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that coul
CVE-2026-3857: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to execute arbitrary GraphQL mutations on behalf of authenticated users due to insufficient CSRF prot
gitlab
CVE-2025-13078MEDIUMCVSS 6.52026-03-25
CVE-2025-13078 [MEDIUM] CWE-1284 CVE-2025-13078: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that coul
CVE-2025-13078: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when processing certain webhoo
gitlab
CVE-2026-2973MEDIUMCVSS 5.42026-03-25
CVE-2026-2973 [MEDIUM] CWE-79 CVE-2026-2973: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could
CVE-2026-2973: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to execute arbitrary JavaScript in a user's browser due to improper sanitization of entity-encoded cont
gitlab
CVE-2026-2745MEDIUMCVSS 6.82026-03-25
CVE-2026-2745 [MEDIUM] CWE-288 CVE-2026-2745: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could
CVE-2026-2745: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to bypass WebAuthn two-factor authentication and gain unauthorized access to user accounts due to in
gitlab
CVE-2026-2726MEDIUMCVSS 4.32026-03-25
CVE-2026-2726 [MEDIUM] CWE-863 CVE-2026-2726: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that coul
CVE-2026-2726: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to perform unauthorized actions on merge requests in other projects due to improper access control du
gitlab
CVE-2025-13436MEDIUMCVSS 6.52026-03-25
CVE-2025-13436 [MEDIUM] CWE-770 CVE-2025-13436: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could
CVE-2025-13436: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when handling certain CI-related
gitlab
CVE-2026-1182MEDIUMCVSS 4.32026-03-12
CVE-2026-1182 [MEDIUM] CWE-212 CVE-2026-1182: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could h
CVE-2026-1182: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to gain unauthorized access to confidential issue title created in public projects under certain circums
gitlab
CVE-2025-14513HIGHCVSS 7.52026-03-11
CVE-2025-14513 [HIGH] CWE-1284 CVE-2025-14513: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could
CVE-2025-14513: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially cr
gitlab
CVE-2025-13929HIGHCVSS 7.52026-03-11
CVE-2025-13929 [HIGH] CWE-770 CVE-2025-13929: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could h
CVE-2025-13929: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by issuing specially crafted requests to repository archive endpoints un
gitlab
CVE-2026-1090HIGHCVSS 8.72026-03-11
CVE-2026-1090 [HIGH] CWE-79 CVE-2026-1090: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could h
CVE-2026-1090: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inject JavaScript in a browser due to improp
gitlab
CVE-2026-1069HIGHCVSS 7.52026-03-11
CVE-2026-1069 [HIGH] CWE-674 CVE-2026-1069: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause
CVE-2026-1069: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by sending specially crafted GraphQL requests due to uncontrolled recursion under certain circumstances.
gitlab
CVE-2025-12576MEDIUMCVSS 6.52026-03-11
CVE-2025-12576 [MEDIUM] CWE-770 CVE-2025-12576: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that under ce
CVE-2025-12576: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that under certain conditions could have allowed an authenticated user to cause a denial of service due to improper handling of webhook response dat
gitlab
CVE-2026-1732MEDIUMCVSS 4.32026-03-11
CVE-2026-1732 [MEDIUM] CWE-212 CVE-2026-1732: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could h
CVE-2026-1732: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose confidential issue titles due to improper filtering under certain circumstances.
gitlab
1 / 29Next →