PatchSiren

GitLab CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH GitLab CVE published 2026-07-29

CVE-2026-6267

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling. This issue has a high severity with a CVSS score of 8.5. The vulnerability w [truncated]

MEDIUM GitLab CVE published 2026-07-29

CVE-2026-3093

CVE-2026-3093 is a vulnerability in GitLab CE/EE that allows an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL. The issue exists in versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 due to improper sanitization of user-controlled input. This vulnerability has a CVSS score of 4.7 (MEDIUM). GitLab administrators and users, security teams, and [truncated]

MEDIUM GitLab CVE published 2026-07-29

CVE-2026-16553

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of upstream requests in virtual registries. This issue is particularly concerning for GitLab EE users and administrators who manage se [truncated]

MEDIUM GitLab CVE published 2026-07-29

CVE-2026-15831

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T20:17:01.983Z and has not been modified since then. The NVD entry is currently Analyzed. GitLab EE administrators and users should prioritize patching for versions 19.1 to 19.1.2 and 19.2. Security teams should review the vulnerability and ensure proper authorization enforcement during token gene [truncated]

MEDIUM GitLab CVE published 2026-07-29

CVE-2026-15077

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T20:17:01.690Z and has not been modified since then. The NVD entry is currently Analyzed. This issue affects GitLab EE versions 19.1 before 19.1.3 and 19.2 before 19.2.1, allowing authenticated users to access information from unauthorized projects due to improper neutralization of untrusted conte [truncated]

MEDIUM GitLab CVE published 2026-07-29

CVE-2026-13113

GitLab EE versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 are affected by a race condition in approval rule processing. This vulnerability could allow an authenticated user to merge code into a protected branch without the required approvals. The issue impacts GitLab EE deployments with specific configurations of protected branches and approval rules. Affected administrators a [truncated]

HIGH GitLab CVE published 2026-07-29

CVE-2026-12436

CVE-2026-12436 is a HIGH-severity vulnerability affecting GitLab CE/EE versions 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1. An authenticated user could modify CI/CD configurations due to improper validation of user-supplied attributes when processing pipeline schedule inputs. This vulnerability allows unauthorized modification of CI/CD configurations, potentially leading to security ri [truncated]

LOW GitLab CVE published 2026-07-29

CVE-2025-14562

GitLab CE/EE versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 have an improper authorization issue. An authenticated user with developer-role permissions could commit changes to a project after being removed as a member. This issue affects GitLab users who manage access permissions and monitor project changes. The vulnerability has been remediated in the mentioned versions. GitLab u [truncated]

MEDIUM GitLab CVE published 2026-07-08

CVE-2026-8472

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with minimal access permissions to read work item metadata from private projects due to missing authorization checks. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. The [truncated]

LOW GitLab CVE published 2026-06-11

CVE-2026-9694

CVE-2026-9694 is a vulnerability in GitLab CE/EE that could allow an unauthenticated user to impersonate the GitLab Support Bot and inject arbitrary content via a specially crafted Service Desk email reply. This issue is due to improper neutralization in email template processing and affects versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.

MEDIUM GitLab CVE published 2026-06-11

CVE-2026-9204

CVE-2026-9204 is a vulnerability in GitLab CE/EE that could allow an authenticated user to read arbitrary files from the Gitaly server and access internal network resources during repository import. This issue affects versions 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.

HIGH GitLab CVE published 2026-06-11

CVE-2026-7250

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsing middleware.

LOW GitLab CVE published 2026-06-11

CVE-2026-6976

CVE-2026-6976 is a low-severity vulnerability in GitLab CE/EE that could allow an authenticated user with developer-role permissions to hide changes from merge request diff views due to improper input handling of file names. The vulnerability affects GitLab versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.

HIGH GitLab CVE published 2026-06-11

CVE-2026-6552

CVE-2026-6552 is a HIGH-severity vulnerability in GitLab EE's Group SAML identity management functionality. An authenticated user with the Group Owner role could, under certain conditions, take over another group member's GitLab account due to improper authorization.

MEDIUM GitLab CVE published 2026-06-11

CVE-2026-6269

CVE-2026-6269 is a medium-severity vulnerability in GitLab CE/EE that could allow an authenticated user with developer-role permissions to modify hidden merge requests due to incorrect authorization enforcements. The vulnerability affects all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.

LOW GitLab CVE published 2026-06-11

CVE-2026-3553

CVE-2026-3553 is a low-severity vulnerability in GitLab CE/EE that could allow an authenticated user to access confidential issue details due to incorrect authorization checks. The issue affects all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.

MEDIUM GitLab CVE published 2026-06-11

CVE-2026-1500

CVE-2026-1500 is a medium-severity vulnerability affecting GitLab CE/EE versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2. The issue could allow an authenticated user to cause denial of service due to uncontrolled resource consumption when processing a specially crafted file upload. The CVSS score for this vulnerability is 6.5, indicating a medium severity.

HIGH GitLab CVE published 2026-06-11

CVE-2026-10087

CVE-2026-10087 is a HIGH-severity vulnerability in GitLab EE. An authenticated user with developer-role permissions could execute arbitrary client-side code on behalf of a targeted user due to improper input sanitization in the Analytics Dashboard. The CVSS score is 8.7.

MEDIUM GitLab CVE published 2026-05-28

CVE-2026-9807

GitLab has remediated an authorization enforcement flaw in GitLab CE/EE where blocked Project Access Tokens could, under certain conditions, continue accessing private resources. The vulnerability affects versions 18.9 through 18.10.6, 18.11 through 18.11.3, and 19.0. Patched versions are 18.10.7, 18.11.4, and 19.0.1. The issue was reported through HackerOne and assigned CWE-863 (Incorrect Authorization). [truncated]

MEDIUM GitLab CVE published 2026-05-27

CVE-2026-8716

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended.

MEDIUM GitLab CVE published 2026-05-27

CVE-2026-6713

GitLab has remediated an authorization bypass vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) that could allow unauthorized users to enumerate private projects. The issue stems from incorrect authorization checks under certain conditions. The vulnerability affects versions 18.2 through 18.10.6, 18.11 through 18.11.3, and version 19.0.0. GitLab released patches on May 27, 2026 in [truncated]

MEDIUM GitLab CVE published 2026-05-27

CVE-2026-5296

GitLab Enterprise Edition (EE) contains an authorization bypass vulnerability affecting the foundational flows feature. When foundational flows are enabled at the group level, an authenticated user with Developer role permissions can bypass flow restrictions under specific conditions. The vulnerability stems from missing authorization checks (CWE-862) in the flow enforcement logic. This is rated MEDIUM se [truncated]

HIGH GitLab CVE published 2026-05-27

CVE-2026-4868

GitLab has remediated an identity confusion vulnerability in GitLab Enterprise Edition (EE) affecting versions 18.8 through 18.10.6, 18.11 through 18.11.3, and 19.0.0. The flaw, rated HIGH severity (CVSS 8.2), stems from CWE-639: Authorization Bypass Through User-Controlled Key. Under specific conditions, an authenticated attacker could cause Duo AI workflow runners to execute under another user's identit [truncated]

MEDIUM GitLab CVE published 2026-05-27

CVE-2026-2601

GitLab has remediated an authorization bypass vulnerability in GitLab Enterprise Edition (EE) that could allow authenticated users with developer-role permissions to access sensitive deployment data on projects. The issue stems from improper authorization checks (CWE-862) and affects versions from 11.5 through 18.10.6, 18.11.0 through 18.11.3, and 19.0.0. GitLab released patches on May 27, 2026 in version [truncated]

MEDIUM GitLab CVE published 2026-05-27

CVE-2026-1402

GitLab has remediated a denial-of-service vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE). The issue, assigned CVSS 3.1 score 6.5 (Medium), stems from insufficient validation that could allow an authenticated user to cause denial of service under certain conditions. The vulnerability affects all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1. Git [truncated]

LOW GitLab CVE published 2026-05-14

CVE-2026-2900

A low-severity vulnerability was discovered in GitLab EE, affecting versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3. The issue allowed an authenticated user with Maintainer permissions to modify or delete project approval rules due to missing authorization checks when instance-level approval rule editing prevention was enabled.

LOW GitLab CVE published 2026-04-08

CVE-2026-4916

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations. This issue has a CVSS score of 2.7 and LOW severity. The vulnerability [truncated]

MEDIUM GitLab CVE published 2026-04-08

CVE-2026-4332

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization. This issue has a CVSS score of 5.4 and is considered Medium severity. Users of [truncated]

MEDIUM GitLab CVE published 2026-04-08

CVE-2026-2619

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization. This issue has a CVSS score of 4.3, indicating a medium severity. The vulnerability all [truncated]

Known exploited GitLab CVE published 2026-02-18

CVE-2021-22175

CVE-2021-22175 is a GitLab server-side request forgery (SSRF) vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. That KEV listing means organizations using GitLab should treat this as a priority remediation item and follow the vendor’s mitigation guidance as soon as possible. The supplied source corpus does not include version ranges, exploitation details, or impact specific [truncated]

Known exploited GitLab CVE published 2026-02-03

CVE-2021-39935

CVE-2021-39935 is a server-side request forgery (SSRF) vulnerability affecting GitLab Community and Enterprise Editions. CISA lists it in the Known Exploited Vulnerabilities catalog, so defenders should treat it as actively exploited and prioritize remediation. The supplied corpus does not include affected version ranges or CVSS scoring, so version-specific exposure should be confirmed against the officia [truncated]

HIGH GitLab CVE published 2026-01-09

CVE-2025-9222

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown. This vulnerability has been addressed in the latest GitLab releases. Users are advised to update to the patched versions to prevent potential e [truncated]

HIGH GitLab CVE published 2026-01-09

CVE-2025-13761

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage. This issue has been patched in GitLab versions 18.6.3 and 18.7.1. Users of affected versions s [truncated]

Known exploited GitLab CVE published 2024-05-01

CVE-2023-7028

CVE-2023-7028 is a GitLab Community and Enterprise Editions improper access control vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-05-01. Because it is listed in KEV, defenders should treat it as an urgent patch-or-mitigate issue for any GitLab CE/EE deployment, especially externally reachable instances. CISA’s guidance is to apply vendor mitigations or discontinue us [truncated]

Known exploited GitLab CVE published 2021-11-03

CVE-2021-22205

CVE-2021-22205 is a GitLab Community and Enterprise Editions remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because CISA also marks the issue as having known ransomware campaign use, it should be treated as an immediate patching priority for any affected GitLab deployment.

HIGH Gitlab CVE published 2017-01-23

CVE-2016-4340

CVE-2016-4340 describes a GitLab impersonation issue in which a remote authenticated user could "log in" as another user through unspecified vectors. NVD rates the issue HIGH (CVSS 3.0 8.8) with network attack scope, low complexity, and no user interaction. The affected range in the NVD corpus spans GitLab 8.2.0 through 8.7.0. Because the issue enables account impersonation, it should be treated as a high [truncated]