Gitlab Ce vulnerabilities

572 known vulnerabilities affecting gitlab/gitlab_ce.

Total CVEs
572
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL18HIGH128MEDIUM342LOW84

Vulnerabilities

Page 5 of 29
CVE-2025-10497HIGHCVSS 7.52025-10-27
CVE-2025-10497 [HIGH] CWE-770 CVE-2025-10497: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could CVE-2025-10497: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.
gitlab
CVE-2025-11974MEDIUMCVSS 6.52025-10-27
CVE-2025-11974 [MEDIUM] CWE-770 CVE-2025-11974: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could h CVE-2025-11974: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints.
gitlab
CVE-2025-10004HIGHCVSS 7.52025-10-09
CVE-2025-10004 [HIGH] CWE-770 CVE-2025-10004: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the Git CVE-2025-10004: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.
gitlab
CVE-2025-2934MEDIUMCVSS 4.32025-10-09
CVE-2025-2934 [MEDIUM] CWE-770 CVE-2025-2934: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that co CVE-2025-2934: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints that send cr
gitlab
CVE-2025-9958HIGHCVSS 7.72025-09-26
CVE-2025-9958 [HIGH] CWE-201 CVE-2025-9958: An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could h CVE-2025-9958: An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.
gitlab
CVE-2025-10858HIGHCVSS 7.52025-09-26
CVE-2025-10858 [HIGH] CWE-770 CVE-2025-10858: An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that allows unauthenticated u CVE-2025-10858: An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that allows unauthenticated users to cause a Denial of Service (DoS) condition while uploading specifically crafted large JSON files.
gitlab
CVE-2025-9642HIGHCVSS 8.72025-09-26
CVE-2025-9642 [HIGH] CWE-79 CVE-2025-9642: An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could al CVE-2025-9642: An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover.
gitlab
CVE-2025-11042MEDIUMCVSS 4.32025-09-26
CVE-2025-11042 [MEDIUM] CWE-770 CVE-2025-11042: An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allo CVE-2025-11042: An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while using specific G
gitlab
CVE-2025-10868LOWCVSS 3.52025-09-26
CVE-2025-10868 [LOW] CWE-840 CVE-2025-10868: An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 where certain CVE-2025-10868: An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 where certain string conversion methods exhibit performance degradation with large inputs.
gitlab
CVE-2025-5069LOWCVSS 3.52025-09-26
CVE-2025-5069 [LOW] CWE-708 CVE-2025-5069: An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could ha CVE-2025-5069: An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to gain unauthorized access to confidential issues by creating a project with an identical name to the victi
gitlab
CVE-2025-10867LOWCVSS 3.52025-09-26
CVE-2025-10867 [LOW] CWE-770 CVE-2025-10867: An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could hav CVE-2025-10867: An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to create a denial-of-service condition by exploiting an unprotected GraphQL API through repeated requests
gitlab
CVE-2025-2256HIGHCVSS 7.52025-09-12
CVE-2025-2256 [HIGH] CWE-1284 CVE-2025-2256: An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could hav CVE-2025-2256: An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML respo
gitlab
CVE-2025-6454HIGHCVSS 8.52025-09-12
CVE-2025-6454 [HIGH] CWE-918 CVE-2025-6454: An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could ha CVE-2025-6454: An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to make unintended internal requests through proxy environments by injecting crafted sequences.
gitlab
CVE-2025-6769MEDIUMCVSS 4.32025-09-12
CVE-2025-6769 [MEDIUM] CWE-497 CVE-2025-6769: An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could hav CVE-2025-6769: An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to view administrator-only maintenance notes by accessing runner details through specific interfaces.
gitlab
CVE-2025-10094MEDIUMCVSS 6.52025-09-12
CVE-2025-10094 [MEDIUM] CWE-1284 CVE-2025-10094: An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could hav CVE-2025-10094: An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrative operations by creating tokens with excess
gitlab
CVE-2025-7337MEDIUMCVSS 6.52025-09-12
CVE-2025-7337 [MEDIUM] CWE-770 CVE-2025-7337: An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have CVE-2025-7337: An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed an authenticated user with Developer-level access to cause a persistent denial of service affecting all users on a GitLab instanc
gitlab
CVE-2025-1250MEDIUMCVSS 6.52025-09-12
CVE-2025-1250 [MEDIUM] CWE-770 CVE-2025-1250: An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could hav CVE-2025-1250: An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed an authenticated user to stall background job processing by sending specially crafted commit messages, merge request description
gitlab
CVE-2025-2246MEDIUMCVSS 5.82025-08-27
CVE-2025-2246 [MEDIUM] CWE-862 CVE-2025-2246: An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed CVE-2025-2246: An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.
gitlab
CVE-2025-5101MEDIUMCVSS 5.02025-08-27
CVE-2025-5101 [MEDIUM] CWE-94 CVE-2025-5101: An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain condi CVE-2025-5101: An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by taking advant
gitlab
CVE-2025-3601MEDIUMCVSS 6.52025-08-27
CVE-2025-3601 [MEDIUM] CWE-770 CVE-2025-3601: An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could hav CVE-2025-3601: An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have could have allowed an authenticated user to cause a Denial of Service (DoS) condition by submitting URLs that generate excessively large
gitlab