GitLab Version Control Server and CI/CD Platform
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in GitLab.
Known Exploited GitLab Vulnerabilities
The following GitLab vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| GitLab Server-Side Request Forgery (SSRF) Vulnerability |
GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled. CVE-2021-22175 Exploit Probability: 53.4% |
February 18, 2026 |
The vulnerability CVE-2021-22175: GitLab Server-Side Request Forgery (SSRF) Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.
GitLab EOL Dates
Ensure that you are using a supported version of GitLab. Here are some end of life, and end of support dates for GitLab.
| Release | EOL | End of Support | Status |
|---|---|---|---|
| 19.3 | November 19, 2026 | September 17, 2026 |
EOL This Year
GitLab 19.3 will become EOL this year, in November 2026. |
| 19.2 | October 15, 2026 | August 20, 2026 |
EOL This Year
GitLab 19.2 will become EOL this year, in October 2026. |
| 19.1 | September 17, 2026 | July 16, 2026 |
EOL This Year
GitLab 19.1 will become EOL this year, in September 2026. |
| 19.0 | August 20, 2026 | June 18, 2026 |
EOL
GitLab 19.0 became EOL in 2026 and supported ended in 2026 |
| 18.11 | July 16, 2026 | May 21, 2026 |
EOL
GitLab 18.11 became EOL in 2026 and supported ended in 2026 |
| 18.9 | May 21, 2026 | March 19, 2026 |
EOL
GitLab 18.9 became EOL in 2026 and supported ended in 2026 |
| 18.8 | April 16, 2026 | February 19, 2026 |
EOL
GitLab 18.8 became EOL in 2026 and supported ended in 2026 |
| 18.7 | March 19, 2026 | January 15, 2026 |
EOL
GitLab 18.7 became EOL in 2026 and supported ended in 2026 |
| 18.6 | February 19, 2026 | December 18, 2025 |
EOL
GitLab 18.6 became EOL in 2026 and supported ended in 2025 |
| 18.5 | January 15, 2026 | November 20, 2025 |
EOL
GitLab 18.5 became EOL in 2026 and supported ended in 2025 |
| 18.4 | December 18, 2025 | October 16, 2025 |
EOL
GitLab 18.4 became EOL in 2025 and supported ended in 2025 |
| 18.3 | November 20, 2025 | September 18, 2025 |
EOL
GitLab 18.3 became EOL in 2025 and supported ended in 2025 |
| 18.2 | October 16, 2025 | August 21, 2025 |
EOL
GitLab 18.2 became EOL in 2025 and supported ended in 2025 |
| 18.1 | September 18, 2025 | July 17, 2025 |
EOL
GitLab 18.1 became EOL in 2025 and supported ended in 2025 |
| 18.0 | August 21, 2025 | June 19, 2025 |
EOL
GitLab 18.0 became EOL in 2025 and supported ended in 2025 |
| 17.11 | July 17, 2025 | May 15, 2025 |
EOL
GitLab 17.11 became EOL in 2025 and supported ended in 2025 |
| 17.9 | May 15, 2025 | March 20, 2025 |
EOL
GitLab 17.9 became EOL in 2025 and supported ended in 2025 |
| 17.8 | April 17, 2025 | February 20, 2025 |
EOL
GitLab 17.8 became EOL in 2025 and supported ended in 2025 |
| 17.7 | March 20, 2025 | January 16, 2025 |
EOL
GitLab 17.7 became EOL in 2025 and supported ended in 2025 |
| 17.6 | February 20, 2025 | December 19, 2024 |
EOL
GitLab 17.6 became EOL in 2025 and supported ended in 2024 |
By the Year
In 2026 there have been 185 vulnerabilities in GitLab with an average score of 5.8 out of ten. Last year, in 2025 GitLab had 161 security vulnerabilities published. That is, 24 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.29
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 185 | 5.77 |
| 2025 | 161 | 6.06 |
| 2024 | 147 | 6.35 |
| 2023 | 178 | 5.57 |
| 2022 | 151 | 5.74 |
| 2021 | 156 | 5.43 |
| 2020 | 235 | 6.16 |
| 2019 | 164 | 6.30 |
| 2018 | 33 | 6.71 |
It may take a day or so for new GitLab vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent GitLab Security Vulnerabilities
GitLab EE <19.3.1: Missing Namespace Validation Enables Auth User Assignment
CVE-2026-4398
5.4 - Medium
- August 27, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from namespaces they were not authorized to access to their own project, due to missing namespace validation on self-managed instances.
Insecure Direct Object Reference / IDOR
GitLab EE SCIM User Provisioning DoS via Unbounded Loop (19.1.7/19.2.5/19.3.1)
CVE-2025-10903
6.5 - Medium
- August 26, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have caused denial of service, due to an unbounded loop triggered by specially crafted input in the SCIM user provisioning feature.
Infinite Loop
GitLab EE Auth Bypass in Protected Env <19.1.7/19.2.5/19.3.1 Improper Authorization
CVE-2026-3035
5.5 - Medium
- August 26, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with project Maintainer permissions could have accessed the terminal of a protected environment they were not authorized to use due to improper authorization checks.
Authentication Bypass Using an Alternate Path or Channel
GitLab EE Auth Escalation: Reset MR Approval Rules (v13.1v19.3.1)
CVE-2026-7487
3.5 - Low
- August 26, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with reporter-role permissions who authored a merge request could have reset merge request approval rules due to improper authorization checks.
Access Control Check Implemented After Asset is Accessed
GitLab EE 19.x Auth Dev-Role Pipeline Exec Policy Bypass via Job Deps
CVE-2026-15387
4.3 - Medium
- August 26, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have influenced the execution environment of Pipeline Execution Policy enforcement jobs, due to improper handling of job dependencies.
Acceptance of Extraneous Untrusted Data With Trusted Data
GitLab Cmd Exec in CI via Claude AG v18.9-<19.1.7,19.2-<19.2.5,19.3-<19.3.1
CVE-2026-18252
7.3 - High
- August 26, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.
Inclusion of Functionality from Untrusted Control Sphere
GitLab CE/EE Auth Denial-of-Service via Missing Object Count Limits v12.8-19.3
CVE-2026-77801
6.5 - Medium
- August 26, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, could have allowed an authenticated user to cause a denial of service affecting background job processing, due to missing object count limits.
Allocation of Resources Without Limits or Throttling
GitLab CE/EE RCE via pkg reg Path Traversal (ver <19.1.4)
CVE-2026-10053
8.5 - High
- August 23, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.
Directory traversal
GitLab v18.2-18.11.10, v19.0-19.0.7, v19.1-19.1.5, v19.2-19.2.3 Unauth GET GraphQL Mut Exec
CVE-2026-19650
7.1 - High
- August 17, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.
Session Riding
GitLab CE/EE <18.11.11, 19.0.0-<19.0.8 allow unauthenticated GraphQL override
CVE-2026-19478
9.4 - Critical
- August 17, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
Code Injection
Privilege Escalation in GitLab EE via Pending Membership (15.6-19.2)
CVE-2025-9486
3.3 - Low
- August 12, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state.
Incorrect Privilege Assignment
GitLab EE Auth Bypass: Dev view of External Status Check via MR API (v1619)
CVE-2026-4879
4.3 - Medium
- August 12, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to view external status check configuration restricted to higher-privileged roles due to missing authorization on a merge request API endpoint.
AuthZ
GitLab EE IP Bypass via Merge Request API v12.0-19.2.2
CVE-2026-6821
4.3 - Medium
- August 12, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to bypass IP-based access restrictions and read limited merge request information from a private project due to missing authorization checks in a merge requests API endpoint.
AuthZ
GitLab CE/EE <=19.2.2 XSS in Analytics Dashboard Table Cells
CVE-2026-15217
8.7 - High
- August 12, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled values rendered in table cell content by an analytics dashboard component.
XSS
GitLab <19.0.6 <19.1.4 <19.2.2 XSS in Analytics Pagination
CVE-2026-15216
8.7 - High
- August 12, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled data rendered in pagination controls by an analytics dashboard component.
XSS
GitLab EE 19.x Auth checks lost - allowed modify project settings
CVE-2026-16494
7.1 - High
- August 12, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization checks on a project update endpoint.
AuthZ
GitLab EE <=19.1.3 & <=19.2.1 GraphQL Auth Bypass unauthorized policy read
CVE-2026-18433
4.3 - Medium
- August 12, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to read policy configuration belonging to a namespace they were not authorized to access, due to incorrect authorization checks in a GraphQL query.
AuthZ
GitLab EE AI Attribution Auth Bypass 19.1-<19.1.4, 19.2-<19.2.2
CVE-2026-19228
8.5 - High
- August 12, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of identity information supplied in requests.
Insecure Direct Object Reference / IDOR
GitLab CE/EE Unauth DoS via Input Validation before 19.2.2
CVE-2026-7427
5.3 - Medium
- August 12, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to improper input validation.
Allocation of Resources Without Limits or Throttling
GitLab CE/EE authz flaw: Dev can alter pkg metadata < v19.2.2
CVE-2026-8667
4.3 - Medium
- August 12, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer role to modify certain package registry metadata without the required maintainer-level permissions due to improper authorization checks.
AuthZ
GitLab 19.x Improper Auth: Dev Role Triggers CI/CD on Protected Branch
CVE-2026-15423
8.5 - High
- August 12, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute CI/CD pipelines on a protected branch without the required push permissions due to improper authorization in pipeline reference validation.
AuthZ
GitLab 19.2 Priv Escalation via CI Job Modal HTML Sanitization (Before 19.2.2)
CVE-2026-16627
7.7 - High
- August 12, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate privileges due to improper sanitization of HTML content rendered in a CI job modal.
XSS
Auth Bypass: GitLab EE 17.719.2.2 Restricted Config Leak
CVE-2026-18244
4.3 - Medium
- August 12, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 17.7 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to view restricted configuration settings due to improper authorization checks on a group settings page.
AuthZ
GitLab CE/EE auth bypass via MR collaboration settings, before 19.2.1
CVE-2025-14562
3.1 - Low
- July 29, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to commit changes to a project after being removed as a member, due to improper authorization checks on merge request collaboration settings.
AuthZ
GitLab JavaScript XSS via crafted URL (v14.019.2.1)
CVE-2026-3093
4.7 - Medium
- July 29, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL, due to improper sanitization of user-controlled input.
XSS
GitLab Access Control Bypass in test reports CE/EE 18.4-19.2.1 (CVE-2026-4672)
CVE-2026-4672
4.3 - Medium
- July 29, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with guest-role permissions to access test report contents they were not authorized to view due to improper access control enforcement.
AuthZ
GitLab CE/EE <=19.0.5 Dev Access Info Disclosure via Internal Requests
CVE-2026-6267
8.5 - High
- July 29, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.
Insertion of Sensitive Information Into Sent Data
Unauthorized Access: GitLab CE/EE v16.6-19.2.1 Project Import Disclosure
CVE-2026-6336
5.3 - Medium
- July 29, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthorized user to view project import source information due to a missing authorization check.
AuthZ
GitLab CE/EE <19.0.5/19.1.3/19.2.1 CI/CD Config Escalation via Pipeline Schedule
CVE-2026-12436
8.4 - High
- July 29, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes when processing pipeline schedule inputs.
Mass Assignment
GitLab EE Merge race (pre-19.0.5) allows approvals bypass
CVE-2026-13113
6.5 - Medium
- July 29, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to merge code into a protected branch without the required approvals due to a race condition in approval rule processing.
TOCTTOU
GitLab API Auth Bypass: Maintainer Can Alter Protected Branches v12.819.2
CVE-2026-14341
4.9 - Medium
- July 29, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Maintainer role to modify protected branch configuration due to improper authorization in a projects API endpoint.
AuthZ
GitLab CE/EE 8.819.2.1 Unauth Issue Title Leak via MR
CVE-2026-14351
4.3 - Medium
- July 29, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to view the title of a confidential issue through a publicly accessible merge request due to improper authorization checks.
Exposure of Sensitive Information Through Metadata
GitLab EE Unauthorized Data Leak via AI Code Review (v19.1<19.1.3 & 19.2<19.2.1)
CVE-2026-15077
4.3 - Medium
- July 29, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to access information from unauthorized projects due to improper neutralization of untrusted content processed by the AI-assisted code review functionality.
1427
GitLab EE Auth Bypass in Token Generation (19.1 < 19.1.3, 19.2 < 19.2.1)
CVE-2026-15831
4.3 - Medium
- July 29, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token generation.
Generation of Incorrect Security Tokens
GitLab CE/EE 19.0.5/19.1<3.3 Unauth DoS via MR Discussions
CVE-2026-15975
7.5 - High
- July 29, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions.
Allocation of Resources Without Limits or Throttling
GitLab EE Virtual Reg Info Disclosure (18.819.2)
CVE-2026-16553
5.4 - Medium
- July 29, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of upstream requests in virtual registries.
Insufficiently Protected Credentials
GitLab Repo Creation Web-Download Mismatch via Improper Git Ref (18.11.7)
CVE-2025-12506
3.5 - Low
- July 08, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web interface differed from the content available for download, due to improper handling of Git reference name resolution.
Use of Incorrectly-Resolved Name or Reference
GitLab EE Auth Bypass: Auditors can alter compliance records via GraphQL
CVE-2026-6352
2.7 - Low
- July 08, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with auditor-level access to modify compliance violation records due to improper authorization on certain GraphQL operations.
AuthZ
GitLab EE: Arbitrary Script Exec via XSS in EE <18.11.7,<19.0.4,<19.1.2
CVE-2026-6896
8.7 - High
- July 08, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.
XSS
GitLab <=18.11.6 Unauth Detect Private Projects via Cross-Project Ref check
CVE-2026-7492
4.3 - Medium
- July 08, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project reference pages.
AuthZ
Auth Bypass: GitLab EE 18.9-18.11.7/19.0-19.0.4/19.1-19.1.2 Reading Metadata
CVE-2026-8472
4.3 - Medium
- July 08, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with minimal access permissions to read work item metadata from private projects due to missing authorization checks.
AuthZ
GitLab EE Auth Bypass: Maintainer Can Read Stored Credentials (v<18.11.7, 19.0<19.0.4, 19.1<19.1.2)
CVE-2026-11827
4.9 - Medium
- July 08, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to obtain another user's stored credentials due to improper authorization controls.
Insufficiently Protected Credentials
Auth Bypass Enables Priv Esc in GitLab EE 16.1018.11.7 / 19.019.0.4 / 19.119.1.2
CVE-2026-13151
- July 08, 2026
GitLab CE/EE XSS: Authenticated exec via improper sanitization (18.11.7, 19.1.2)
CVE-2026-13320
7.3 - High
- July 08, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.
XSS
GitLab EE 18.11.6/19.0.3/19.1.1: Dev role XSS via code exec
CVE-2026-10086
8.7 - High
- June 25, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in the context of another user's session, due to improper sanitization of user-supplied input.
XSS
GitLab EE: Auth Priv Access to Env Configs (v17.9-18.11,19.0-19.0,19.1-19.1)
CVE-2026-0934
3.8 - Low
- June 25, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with custom role permissions to view, create, or delete protected environment configurations despite CI/CD visibility being disabled for the project.
AuthZ
GitLab CE/EE Snippet Escalation (18.11.5, 19.0.2, 19.1.0)
CVE-2026-1606
4.3 - Medium
- June 25, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation.
Code Injection
GitLab CE/EE <18.11.6/19.0.3/19.1.1 Unauthorized Confidential Issue Ref Access
CVE-2026-2238
5.3 - Medium
- June 25, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to view confidential issue references on public projects due to improper authorization checks.
AuthZ
GitLab EE 18.618.11.5/19.0/19.1 AuthZ Bypass (Limited Auth)
CVE-2026-3176
3.1 - Low
- June 25, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited permissions to access project information due to insufficient authorization checks.
AuthZ
Unauth Access to GitLab EE Virtual Registry Cleanup Policy (18.11.6, 19.1.1)
CVE-2026-5309
5.4 - Medium
- June 25, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to read or modify another group's virtual registry cleanup policy settings without authorization.
Insecure Direct Object Reference / IDOR