Gitlab Ce vulnerabilities
572 known vulnerabilities affecting gitlab/gitlab_ce.
Total CVEs
572
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL18HIGH128MEDIUM342LOW84
Vulnerabilities
Page 2 of 29
CVE-2026-1663MEDIUMCVSS 4.32026-03-11
CVE-2026-1663 [MEDIUM] CWE-862 CVE-2026-1663: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could h
CVE-2026-1663: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with group import permissions to create labels in private projects due to improper authorization validat
gitlab
CVE-2026-0602MEDIUMCVSS 4.32026-03-11
CVE-2026-0602 [MEDIUM] CWE-288 CVE-2026-0602: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could h
CVE-2026-0602: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose metadata from private issues, merge requests, epics, milestones, or commits due to improper
gitlab
CVE-2026-1230MEDIUMCVSS 4.12026-03-11
CVE-2026-1230 [MEDIUM] CWE-706 CVE-2026-1230: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could ha
CVE-2026-1230: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause repository downloads to contain different code than displayed in the web interface due to incorr
gitlab
CVE-2025-12555MEDIUMCVSS 4.32026-03-11
CVE-2025-12555 [MEDIUM] CWE-863 CVE-2025-12555: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that, under
CVE-2025-12555: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that, under certain conditions, could have allowed an authenticated user to access previous pipeline job information on projects with repository and
gitlab
CVE-2025-13690MEDIUMCVSS 6.52026-03-11
CVE-2025-13690 [MEDIUM] CWE-770 CVE-2025-13690: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could
CVE-2025-13690: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause a denial of service condition due to improper input validation on webhook custom header name
gitlab
CVE-2026-3848MEDIUMCVSS 5.02026-03-11
CVE-2026-3848 [MEDIUM] CWE-93 CVE-2026-3848: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could h
CVE-2026-3848: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to make unintended internal requests through proxy environments under certain conditions due to improper
gitlab
CVE-2025-12697LOWCVSS 2.22026-03-11
CVE-2025-12697 [LOW] CWE-116 CVE-2025-12697: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could h
CVE-2025-12697: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API credentials under certain conditions.
gitlab
CVE-2025-14511HIGHCVSS 7.52026-02-25
CVE-2025-14511 [HIGH] CWE-1284 CVE-2025-14511: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could h
CVE-2025-14511: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted files to the container registry event endpoi
gitlab
CVE-2026-1662HIGHCVSS 7.52026-02-25
CVE-2026-1662 [HIGH] CWE-770 CVE-2026-1662: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could h
CVE-2026-1662: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause Denial of Service by sending specially crafted requests to the Jira events endpoint.
gitlab
CVE-2026-0752HIGHCVSS 8.02026-02-25
CVE-2026-0752 [HIGH] CWE-79 CVE-2026-0752: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that under c
CVE-2026-0752: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that under certain circumstances, could have allowed an unauthenticated user to inject arbitrary scripts into the Mermaid sandbox UI.
gitlab
CVE-2026-1388HIGHCVSS 7.52026-02-25
CVE-2026-1388 [HIGH] CWE-1333 CVE-2026-1388: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could ha
CVE-2026-1388: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause regular expression denial of service by sending specially crafted input to a merge request endp
gitlab
CVE-2026-1725MEDIUMCVSS 5.32026-02-25
CVE-2026-1725 [MEDIUM] CWE-770 CVE-2026-1725: GitLab has remediated an issue in GitLab CE/EE affecting versions from 18.9 before 18.9.1 that could have under certain conditions, allowed an unauthe
CVE-2026-1725: GitLab has remediated an issue in GitLab CE/EE affecting versions from 18.9 before 18.9.1 that could have under certain conditions, allowed an unauthenticated user to cause denial of service by sending specially crafted requests to a CI jobs API endpoint.
gitlab
CVE-2026-2845MEDIUMCVSS 6.52026-02-25
CVE-2026-2845 [MEDIUM] CWE-770 CVE-2026-2845: An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could hav
CVE-2026-2845: An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an authenticated user to cause denial of service by exploiting a Bitbucket Server import endpoint via repeatedly sending large r
gitlab
CVE-2025-14103MEDIUMCVSS 4.32026-02-25
CVE-2025-14103 [MEDIUM] CWE-862 CVE-2025-14103: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could h
CVE-2025-14103: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthorized user with Developer-role permissions to set pipeline variables for manually triggered jobs under certain co
gitlab
CVE-2025-3525MEDIUMCVSS 6.52026-02-25
CVE-2025-3525 [MEDIUM] CWE-770 CVE-2025-3525: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could ha
CVE-2025-3525: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have, under certain circumstances, allowed an authenticated user with certain access to cause Denial of Service by creating specially crafte
gitlab
CVE-2025-7659HIGHCVSS 8.02026-02-11
CVE-2025-7659 [HIGH] CWE-346 CVE-2025-7659: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could h
CVE-2025-7659: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to steal tokens and access private repositories by abusing incomplete validation in the Web IDE.
gitlab
CVE-2026-0595HIGHCVSS 7.32026-02-11
CVE-2026-0595 [HIGH] CWE-79 CVE-2026-0595: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under
CVE-2026-0595: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to add unauthorized email addresses to victim accounts through HTML injection in t
gitlab
CVE-2026-0958HIGHCVSS 7.52026-02-11
CVE-2026-0958 [HIGH] CWE-436 CVE-2026-0958: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could h
CVE-2026-0958: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through memory or CPU exhaustion by bypassing JSON validation middleware limi
gitlab
CVE-2025-8099HIGHCVSS 7.52026-02-11
CVE-2025-8099 [HIGH] CWE-770 CVE-2025-8099: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under
CVE-2025-8099: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.
gitlab
CVE-2025-14560HIGHCVSS 7.32026-02-11
CVE-2025-14560 [HIGH] CWE-79 CVE-2025-14560: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under
CVE-2025-14560: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by injecting maliciou
gitlab