GitLab GitLab GitLab Version Control Server

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any GitLab product.

RSS Feeds for GitLab security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in GitLab products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by GitLab Sorted by Most Security Vulnerabilities since 2018

GitLab1438 vulnerabilities
Version Control Server and CI/CD Platform

GitLab Ai Gateway4 vulnerabilities

GitLab Gitaly3 vulnerabilities

GitLab Runner2 vulnerabilities

GitLab 1 vulnerability

GitLab Dast Api Scanner1 vulnerability

Gitlab Runner1 vulnerability

Gitlab Vscode Extension1 vulnerability

GitLab Language Server1 vulnerability

GitLab Omnibus1 vulnerability

Known Exploited GitLab Vulnerabilities

The following GitLab vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.
CVE-2026-85706
September 11, 2026
GitLab Server-Side Request Forgery (SSRF) Vulnerability GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.
CVE-2021-22175 Exploit Probability: 53.4%
February 18, 2026
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.
CVE-2021-39935 Exploit Probability: 35.6%
February 3, 2026
GitLab Community and Enterprise Editions Improper Access Control Vulnerability GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.
CVE-2023-7028 Exploit Probability: 94.6%
May 1, 2024

The vulnerability CVE-2023-7028: GitLab Community and Enterprise Editions Improper Access Control Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. 2 known exploited GitLab vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 219 vulnerabilities in GitLab with an average score of 5.9 out of ten. Last year, in 2025 GitLab had 162 security vulnerabilities published. That is, 57 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.20




Year Vulnerabilities Average Score
2026 219 5.89
2025 162 6.09
2024 147 6.35
2023 183 5.60
2022 152 5.75
2021 157 5.44
2020 237 6.15
2019 165 6.33
2018 33 6.71

It may take a day or so for new GitLab vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent GitLab Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-90970 Oct 02, 2026
GitLab AI Gateway Prompt Sandbox Escape CVE-2026-90970 (18.1.6-19.4.1) GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.
Ai Gateway
CVE-2026-4523 Sep 29, 2026
GitLab CE/EE CI/CD Trace Read Auth Flaw 15.11-19.4 via GraphQL API GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthenticated user to read CI/CD job trace contents containing sensitive variable values due to improper authorization enforcement in the GraphQL API.
GitLab
CVE-2026-8937 Sep 29, 2026
GitLab CE/EE 19.0-19.4.1 Auth Bypass on Linked Work Items GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to read private child issue contents, including titles and descriptions, from projects they had no access to, due to missing authorization checks on linked work items within visible epics.
GitLab
CVE-2026-10518 Sep 29, 2026
GitLab EE Auth Bypass in EE 17.9-19.4.1: Guest can read private security policy GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with guest-level permissions to read private security policy content they were not authorized to access due to improper authorization enforcement.
GitLab
CVE-2026-84739 Sep 29, 2026
GitLab CE/EE XSS in MR Diff Viewer (v19.4.1) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary JavaScript in the context of another user's browser session due to improper sanitization of path components in the merge request diff viewer.
GitLab
CVE-2026-89078 Sep 23, 2026
GitLab CE/EE double free in CI/CD regex parsing (19.2-19.4) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a specially crafted regular expression in a CI/CD configuration.
GitLab
CVE-2026-92530 Sep 23, 2026
GitLab CE/EE Auth Spoof via Direct Transfer Import (v19.1-19.4) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to spoof merge request authorship and attribute content to arbitrary existing users on the target instance due to improper reliance on ephemeral cache state during Direct Transfer imports.
GitLab
CVE-2026-92470 Sep 23, 2026
GitLab EE 18.719.4.1 AuthZ flaw: Auth users read CI/CD vars via Duo AI GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to access sensitive CI/CD variable values from debug-mode job traces through the Duo AI troubleshooting feature due to missing authorization checks.
GitLab
CVE-2026-92529 Sep 23, 2026
GitLab EE 19.1-19.4 (pre-19.2.7/19.3.3/19.4.1) AI Governance Bypass (Auth) GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass admin-configured AI tool governance controls for workflows in namespaces they do not control due to improper authorization checks.
GitLab
CVE-2026-92874 Sep 23, 2026
GitLab <19.4 Improper Auth Allows MCP Token Scope Escalation GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with an MCP-scoped token to perform actions beyond the intended scope of that token due to improper authorization checks.
GitLab
CVE-2026-92628 Sep 23, 2026
GitLab CE/EE 18.619.4.1 Race Cond in MCP Search GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race condition, the MCP search tool's shared state handling could have caused search results to be returned under an incorrect user context.
GitLab
CVE-2026-93577 Sep 23, 2026
GitLab CE 19.2-19.4 CI/CD Regex Integer Overflow (arbitrary code) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.
GitLab
CVE-2026-86341 Sep 16, 2026
GitLab EE: Improper Access Control Lets Owner Disable Protected Env Approval GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user with Owner or Maintainer permissions could have silently disabled protected environment deployment approval requirements, allowing unapproved deployments to reach production, due to improper access control checks performed after the protected resource was modified.
GitLab
CVE-2024-11222 Sep 16, 2026
GitLab CE/EE Race Condition in Pipeline Creation (beyond 19.1.8, 19.2.6, 19.3.2) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed a developer user to perform actions in the context of another user's merge request commit due to a race condition issue in pipeline creation.
GitLab
CVE-2025-14871 Sep 16, 2026
GitLab GraphQL DoS via Complexity Calculation (v<19.3.2) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation limits in the GraphQL complexity calculation logic.
GitLab
CVE-2026-1168 Sep 16, 2026
GitLab CE/EE DoS via GraphQL Complexity Calc (18.4.6-19.3.1) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation limits in the GraphQL complexity calculation logic.
GitLab
CVE-2026-3855 Sep 16, 2026
GitLab CE/EE 18.x-19.3: Authenticated FS Disclosure via Terraform State Upload (CVE-2026-3855) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user with project-level permissions to access restricted file contents on the server or cause denial of service due to improper validation of parameters in the Terraform state upload functionality.
GitLab
CVE-2026-7514 Sep 16, 2026
GitLab GenPkg Registry Auth Bypass 13.9-19.1.8/19.2-19.2.6/19.3-19.3.2 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that an authenticated user with developer-role permissions could substitute package file content and hide packages from their owners due to improper authorization checks in the Generic Package Registry.
GitLab
CVE-2026-8030 Sep 16, 2026
GitLab auth group URL slug flaw (v13.0-19.1.8,19.2-19.2.6,19.3-19.3.2) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to prevent another user from modifying their group settings due to improper validation of group URL slugs during namespace transfers.
GitLab
CVE-2026-16794 Sep 16, 2026
GitLab EE 18.11-19.3.2 auth flaw: Execute CI/CD jobs as Security Manager GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user with the Security Manager role to execute arbitrary CI/CD jobs and access protected variables within group projects due to improper authorization controls on compliance framework management.
GitLab
CVE-2026-19619 Sep 16, 2026
GitLab CE/EE 19.x XSS via Content Editor (up to 19.3.2) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in the context of a targeted user's session due to improper sanitization of pasted HTML content in the Content Editor.
GitLab
CVE-2026-78252 Sep 16, 2026
GitLab Markdown JSON Table CSRF in CE/EE before 19.3.2 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user could have induced a targeted user to perform unintended state-changing HTTP requests due to improper sanitization of user-controlled data in the Markdown JSON table renderer.
GitLab
CVE-2026-79708 Sep 16, 2026
Insufficient Scope Validation in GL EE 19.0-19.3: Devs access vars & pipelines GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to execute a policy test pipeline on projects within their group and access protected CI/CD variables restricted to higher-privileged roles, due to insufficient scope validation.
GitLab
CVE-2026-12910 Sep 15, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to bypass SAML SSO sign-in restrictions and authenticate without SSO due to missing authentication enforcement checks.
GitLab
CVE-2026-13210 Sep 15, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to access CI/CD variables outside their intended environment scope due to improper input validation in the environment scope pattern matcher.
GitLab
CVE-2026-82837 Sep 15, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials and tokens without transiting the expected proxy due to improper authorization checks on internal data emission endpoints.
GitLab
CVE-2026-88765 Sep 15, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a specially crafted Git project export to overflow the Unicode conversion buffer used in Advanced Search indexing.
GitLab
CVE-2026-85706 Sep 12, 2026
GitLab File Read via Unauth Repo Commits API (18.7-19.3.x) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
GitLab
CVE-2026-87719 Sep 12, 2026
GitLab EE Advanced Search Leak via GraphQL sub (v18.3-<19.1.8,19.2-<19.2.6,19.3-<19.3.2) GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.
GitLab
CVE-2026-4398 Aug 27, 2026
GitLab EE <19.3.1: Missing Namespace Validation Enables Auth User Assignment GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from namespaces they were not authorized to access to their own project, due to missing namespace validation on self-managed instances.
GitLab
CVE-2026-75871 Aug 27, 2026
GitLab AI Gateway Auth Bypass via Host Header Override (18.10-19.2.2) GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect outbound model requests to an externally-controlled endpoint via a crafted inline flow configuration that overrides the HTTP Host header, resulting in disclosure of Google Cloud Vertex cloud service credentials and private signing keys.
Ai Gateway
CVE-2026-19889 Aug 27, 2026
GitLab AI Gateway Auth Bypass via External Endpoint Redirect (18.9.0-19.2.2) GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.9.0 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect model requests to an externally-controlled endpoint via crafted model metadata, resulting in the disclosure of Google Vertex AI or AWS Bedrock cloud service credentials.
Ai Gateway
CVE-2025-10903 Aug 26, 2026
GitLab EE SCIM User Provisioning DoS via Unbounded Loop (19.1.7/19.2.5/19.3.1) GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have caused denial of service, due to an unbounded loop triggered by specially crafted input in the SCIM user provisioning feature.
GitLab
CVE-2026-3035 Aug 26, 2026
GitLab EE Auth Bypass in Protected Env <19.1.7/19.2.5/19.3.1 Improper Authorization GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with project Maintainer permissions could have accessed the terminal of a protected environment they were not authorized to use due to improper authorization checks.
GitLab
CVE-2026-7487 Aug 26, 2026
GitLab EE Auth Escalation: Reset MR Approval Rules (v13.1v19.3.1) GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with reporter-role permissions who authored a merge request could have reset merge request approval rules due to improper authorization checks.
GitLab
CVE-2026-15387 Aug 26, 2026
GitLab EE 19.x Auth Dev-Role Pipeline Exec Policy Bypass via Job Deps GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have influenced the execution environment of Pipeline Execution Policy enforcement jobs, due to improper handling of job dependencies.
GitLab
CVE-2026-18252 Aug 26, 2026
GitLab Cmd Exec in CI via Claude AG v18.9-<19.1.7,19.2-<19.2.5,19.3-<19.3.1 GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.
GitLab
CVE-2026-77801 Aug 26, 2026
GitLab CE/EE Auth Denial-of-Service via Missing Object Count Limits v12.8-19.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, could have allowed an authenticated user to cause a denial of service affecting background job processing, due to missing object count limits.
GitLab
CVE-2026-10053 Aug 23, 2026
GitLab CE/EE RCE via pkg reg Path Traversal (ver <19.1.4) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.
GitLab
CVE-2026-19650 Aug 17, 2026
GitLab v18.2-18.11.10, v19.0-19.0.7, v19.1-19.1.5, v19.2-19.2.3 Unauth GET GraphQL Mut Exec GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.
GitLab
CVE-2026-19478 Aug 17, 2026
GitLab CE/EE <18.11.11, 19.0.0-<19.0.8 allow unauthenticated GraphQL override GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
GitLab
CVE-2025-9486 Aug 12, 2026
Privilege Escalation in GitLab EE via Pending Membership (15.6-19.2) GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state.
GitLab
CVE-2026-4879 Aug 12, 2026
GitLab EE Auth Bypass: Dev view of External Status Check via MR API (v1619) GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to view external status check configuration restricted to higher-privileged roles due to missing authorization on a merge request API endpoint.
GitLab
CVE-2026-6821 Aug 12, 2026
GitLab EE IP Bypass via Merge Request API v12.0-19.2.2 GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to bypass IP-based access restrictions and read limited merge request information from a private project due to missing authorization checks in a merge requests API endpoint.
GitLab
CVE-2026-15217 Aug 12, 2026
GitLab CE/EE <=19.2.2 XSS in Analytics Dashboard Table Cells GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled values rendered in table cell content by an analytics dashboard component.
GitLab
CVE-2026-15216 Aug 12, 2026
GitLab <19.0.6 <19.1.4 <19.2.2 XSS in Analytics Pagination GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled data rendered in pagination controls by an analytics dashboard component.
GitLab
CVE-2026-16494 Aug 12, 2026
GitLab EE 19.x Auth checks lost - allowed modify project settings GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization checks on a project update endpoint.
GitLab
CVE-2026-18433 Aug 12, 2026
GitLab EE <=19.1.3 & <=19.2.1 GraphQL Auth Bypass unauthorized policy read GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to read policy configuration belonging to a namespace they were not authorized to access, due to incorrect authorization checks in a GraphQL query.
GitLab
CVE-2026-19228 Aug 12, 2026
GitLab EE AI Attribution Auth Bypass 19.1-<19.1.4, 19.2-<19.2.2 GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of identity information supplied in requests.
GitLab
CVE-2026-7427 Aug 12, 2026
GitLab CE/EE Unauth DoS via Input Validation before 19.2.2 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to improper input validation.
GitLab
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.