Gitlab Ce vulnerabilities

572 known vulnerabilities affecting gitlab/gitlab_ce.

Total CVEs
572
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL18HIGH128MEDIUM342LOW84

Vulnerabilities

Page 3 of 29
CVE-2026-1456MEDIUMCVSS 6.52026-02-11
CVE-2026-1456 [MEDIUM] CWE-770 CVE-2026-1456: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unaut CVE-2026-1456: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential
gitlab
CVE-2026-1094MEDIUMCVSS 4.62026-02-11
CVE-2026-1094 [MEDIUM] CWE-1289 CVE-2026-1094: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an authenticated developer to hi CVE-2026-1094: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an authenticated developer to hide specially crafted file changes from the WebUI.
gitlab
CVE-2025-12073MEDIUMCVSS 4.32026-02-11
CVE-2025-12073 [MEDIUM] CWE-918 CVE-2025-12073: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under CVE-2025-12073: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an authenticated user to perform server-side request forgery against internal services by bypassi
gitlab
CVE-2026-1458MEDIUMCVSS 6.52026-02-11
CVE-2026-1458 [MEDIUM] CWE-770 CVE-2026-1458: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under c CVE-2026-1458: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service by uploading malicious files.
gitlab
CVE-2025-14592LOWCVSS 3.72026-02-11
CVE-2025-14592 [LOW] CWE-862 CVE-2025-14592: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under CVE-2025-14592: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized operations by submitting GraphQL mutations through the
gitlab
CVE-2026-1282LOWCVSS 3.52026-02-11
CVE-2026-1282 [LOW] CWE-80 CVE-2026-1282: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could h CVE-2026-1282: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to inject malicious content into project labels titles.
gitlab
CVE-2025-14594LOWCVSS 3.52026-02-11
CVE-2025-14594 [LOW] CWE-639 CVE-2025-14594: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under CVE-2025-14594: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view certain pipeline values by querying the API.
gitlab
CVE-2026-1751LOWCVSS 3.12026-02-02
CVE-2026-1751 [LOW] CWE-862 CVE-2026-1751: A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits CVE-2026-1751: A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.
gitlab
CVE-2025-13927HIGHCVSS 7.52026-01-22
CVE-2025-13927 [HIGH] CWE-770 CVE-2025-13927: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could h CVE-2025-13927: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted requests with malformed authentication dat
gitlab
CVE-2026-0723HIGHCVSS 7.42026-01-22
CVE-2026-0723 [HIGH] CWE-252 CVE-2026-0723: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could h CVE-2026-0723: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an individual with existing knowledge of a victim's credential ID to bypass two-factor authentication by submitting forged devic
gitlab
CVE-2025-13928HIGHCVSS 7.52026-01-22
CVE-2025-13928 [HIGH] CWE-863 CVE-2025-13928: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could h CVE-2025-13928: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to cause a denial of service condition by exploiting incorrect authorization validation in API endpoi
gitlab
CVE-2025-13335MEDIUMCVSS 6.52026-01-22
CVE-2025-13335 [MEDIUM] CWE-835 CVE-2025-13335: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under c CVE-2025-13335: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under certain circumstances could have allowed an authenticated user to create a denial of service condition by configuring malformed Wiki doc
gitlab
CVE-2026-1102MEDIUMCVSS 5.32026-01-22
CVE-2026-1102 [MEDIUM] CWE-770 CVE-2026-1102: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could h CVE-2026-1102: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending repeated malformed SSH authentication requests.
gitlab
CVE-2025-11224HIGHCVSS 7.72026-01-14
CVE-2025-11224 [HIGH] CWE-79 CVE-2025-11224: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could CVE-2025-11224: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to execute stored cross-site scripting through improper input validation in the Kubernetes proxy functio
gitlab
CVE-2025-9222HIGHCVSS 8.72026-01-09
CVE-2025-9222 [HIGH] CWE-79 CVE-2025-9222: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could CVE-2025-9222: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.
gitlab
CVE-2025-13761HIGHCVSS 8.02026-01-09
CVE-2025-13761 [HIGH] CWE-79 CVE-2025-13761: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unaut CVE-2025-13761: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a s
gitlab
CVE-2025-10569MEDIUMCVSS 6.52026-01-09
CVE-2025-10569 [MEDIUM] CWE-770 CVE-2025-10569: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could ha CVE-2025-10569: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to create a denial of service condition by providing crafted responses to external API calls.
gitlab
CVE-2025-11246MEDIUMCVSS 5.42026-01-09
CVE-2025-11246 [MEDIUM] CWE-1220 CVE-2025-11246: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could h CVE-2025-11246: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user with specific permissions to remove all project runners from unrelated projects by manipulating Grap
gitlab
CVE-2025-3950LOWCVSS 3.52026-01-09
CVE-2025-3950 [LOW] CWE-359 CVE-2025-3950: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could h CVE-2025-3950: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.
gitlab
CVE-2025-12029HIGHCVSS 8.02025-12-11
CVE-2025-12029 [HIGH] CWE-79 CVE-2025-12029: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could CVE-2025-12029: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting m
gitlab
Gitlab Ce vulnerabilities | cvebase