These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling. This issue has a high severity with a CVSS score of 8.5. The vulnerability w [truncated]
CVE-2026-3093 is a vulnerability in GitLab CE/EE that allows an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL. The issue exists in versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 due to improper sanitization of user-controlled input. This vulnerability has a CVSS score of 4.7 (MEDIUM). GitLab administrators and users, security teams, and [truncated]
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of upstream requests in virtual registries. This issue is particularly concerning for GitLab EE users and administrators who manage se [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T20:17:01.983Z and has not been modified since then. The NVD entry is currently Analyzed. GitLab EE administrators and users should prioritize patching for versions 19.1 to 19.1.2 and 19.2. Security teams should review the vulnerability and ensure proper authorization enforcement during token gene [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T20:17:01.690Z and has not been modified since then. The NVD entry is currently Analyzed. This issue affects GitLab EE versions 19.1 before 19.1.3 and 19.2 before 19.2.1, allowing authenticated users to access information from unauthorized projects due to improper neutralization of untrusted conte [truncated]
GitLab EE versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 are affected by a race condition in approval rule processing. This vulnerability could allow an authenticated user to merge code into a protected branch without the required approvals. The issue impacts GitLab EE deployments with specific configurations of protected branches and approval rules. Affected administrators a [truncated]
CVE-2026-12436 is a HIGH-severity vulnerability affecting GitLab CE/EE versions 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1. An authenticated user could modify CI/CD configurations due to improper validation of user-supplied attributes when processing pipeline schedule inputs. This vulnerability allows unauthorized modification of CI/CD configurations, potentially leading to security ri [truncated]
GitLab CE/EE versions 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 have an improper authorization issue. An authenticated user with developer-role permissions could commit changes to a project after being removed as a member. This issue affects GitLab users who manage access permissions and monitor project changes. The vulnerability has been remediated in the mentioned versions. GitLab u [truncated]
GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with minimal access permissions to read work item metadata from private projects due to missing authorization checks. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. The [truncated]
CVE-2026-9694 is a vulnerability in GitLab CE/EE that could allow an unauthenticated user to impersonate the GitLab Support Bot and inject arbitrary content via a specially crafted Service Desk email reply. This issue is due to improper neutralization in email template processing and affects versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.
CVE-2026-9204 is a vulnerability in GitLab CE/EE that could allow an authenticated user to read arbitrary files from the Gitaly server and access internal network resources during repository import. This issue affects versions 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsing middleware.
CVE-2026-6976 is a low-severity vulnerability in GitLab CE/EE that could allow an authenticated user with developer-role permissions to hide changes from merge request diff views due to improper input handling of file names. The vulnerability affects GitLab versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.
CVE-2026-6552 is a HIGH-severity vulnerability in GitLab EE's Group SAML identity management functionality. An authenticated user with the Group Owner role could, under certain conditions, take over another group member's GitLab account due to improper authorization.
CVE-2026-6269 is a medium-severity vulnerability in GitLab CE/EE that could allow an authenticated user with developer-role permissions to modify hidden merge requests due to incorrect authorization enforcements. The vulnerability affects all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.
CVE-2026-3553 is a low-severity vulnerability in GitLab CE/EE that could allow an authenticated user to access confidential issue details due to incorrect authorization checks. The issue affects all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.
CVE-2026-1500 is a medium-severity vulnerability affecting GitLab CE/EE versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2. The issue could allow an authenticated user to cause denial of service due to uncontrolled resource consumption when processing a specially crafted file upload. The CVSS score for this vulnerability is 6.5, indicating a medium severity.
CVE-2026-10087 is a HIGH-severity vulnerability in GitLab EE. An authenticated user with developer-role permissions could execute arbitrary client-side code on behalf of a targeted user due to improper input sanitization in the Analytics Dashboard. The CVSS score is 8.7.
GitLab has remediated an authorization enforcement flaw in GitLab CE/EE where blocked Project Access Tokens could, under certain conditions, continue accessing private resources. The vulnerability affects versions 18.9 through 18.10.6, 18.11 through 18.11.3, and 19.0. Patched versions are 18.10.7, 18.11.4, and 19.0.1. The issue was reported through HackerOne and assigned CWE-863 (Incorrect Authorization). [truncated]
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended.
GitLab has remediated an authorization bypass vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) that could allow unauthorized users to enumerate private projects. The issue stems from incorrect authorization checks under certain conditions. The vulnerability affects versions 18.2 through 18.10.6, 18.11 through 18.11.3, and version 19.0.0. GitLab released patches on May 27, 2026 in [truncated]
GitLab Enterprise Edition (EE) contains an authorization bypass vulnerability affecting the foundational flows feature. When foundational flows are enabled at the group level, an authenticated user with Developer role permissions can bypass flow restrictions under specific conditions. The vulnerability stems from missing authorization checks (CWE-862) in the flow enforcement logic. This is rated MEDIUM se [truncated]
GitLab has remediated an identity confusion vulnerability in GitLab Enterprise Edition (EE) affecting versions 18.8 through 18.10.6, 18.11 through 18.11.3, and 19.0.0. The flaw, rated HIGH severity (CVSS 8.2), stems from CWE-639: Authorization Bypass Through User-Controlled Key. Under specific conditions, an authenticated attacker could cause Duo AI workflow runners to execute under another user's identit [truncated]
GitLab has remediated an authorization bypass vulnerability in GitLab Enterprise Edition (EE) that could allow authenticated users with developer-role permissions to access sensitive deployment data on projects. The issue stems from improper authorization checks (CWE-862) and affects versions from 11.5 through 18.10.6, 18.11.0 through 18.11.3, and 19.0.0. GitLab released patches on May 27, 2026 in version [truncated]
GitLab has remediated a denial-of-service vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE). The issue, assigned CVSS 3.1 score 6.5 (Medium), stems from insufficient validation that could allow an authenticated user to cause denial of service under certain conditions. The vulnerability affects all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1. Git [truncated]
A low-severity vulnerability was discovered in GitLab EE, affecting versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3. The issue allowed an authenticated user with Maintainer permissions to modify or delete project approval rules due to missing authorization checks when instance-level approval rule editing prevention was enabled.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations. This issue has a CVSS score of 2.7 and LOW severity. The vulnerability [truncated]
GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization. This issue has a CVSS score of 5.4 and is considered Medium severity. Users of [truncated]
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization. This issue has a CVSS score of 4.3, indicating a medium severity. The vulnerability all [truncated]
CVE-2021-22175 is a GitLab server-side request forgery (SSRF) vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. That KEV listing means organizations using GitLab should treat this as a priority remediation item and follow the vendor’s mitigation guidance as soon as possible. The supplied source corpus does not include version ranges, exploitation details, or impact specific [truncated]
CVE-2021-39935 is a server-side request forgery (SSRF) vulnerability affecting GitLab Community and Enterprise Editions. CISA lists it in the Known Exploited Vulnerabilities catalog, so defenders should treat it as actively exploited and prioritize remediation. The supplied corpus does not include affected version ranges or CVSS scoring, so version-specific exposure should be confirmed against the officia [truncated]
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown. This vulnerability has been addressed in the latest GitLab releases. Users are advised to update to the patched versions to prevent potential e [truncated]
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage. This issue has been patched in GitLab versions 18.6.3 and 18.7.1. Users of affected versions s [truncated]
CVE-2023-7028 is a GitLab Community and Enterprise Editions improper access control vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-05-01. Because it is listed in KEV, defenders should treat it as an urgent patch-or-mitigate issue for any GitLab CE/EE deployment, especially externally reachable instances. CISA’s guidance is to apply vendor mitigations or discontinue us [truncated]
CVE-2021-22205 is a GitLab Community and Enterprise Editions remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because CISA also marks the issue as having known ransomware campaign use, it should be treated as an immediate patching priority for any affected GitLab deployment.
CVE-2016-4340 describes a GitLab impersonation issue in which a remote authenticated user could "log in" as another user through unspecified vectors. NVD rates the issue HIGH (CVSS 3.0 8.8) with network attack scope, low complexity, and no user interaction. The affected range in the NVD corpus spans GitLab 8.2.0 through 8.7.0. Because the issue enables account impersonation, it should be treated as a high [truncated]