These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
GitLab Enterprise Edition (EE) contains an authorization bypass vulnerability affecting the foundational flows feature. When foundational flows are enabled at the group level, an authenticated user with Developer role permissions can bypass flow restrictions under specific conditions. The vulnerability stems from missing authorization checks (CWE-862) in the flow enforcement logic. This is rated MEDIUM se [truncated]
GitLab has remediated an identity confusion vulnerability in GitLab Enterprise Edition (EE) affecting versions 18.8 through 18.10.6, 18.11 through 18.11.3, and 19.0.0. The flaw, rated HIGH severity (CVSS 8.2), stems from CWE-639: Authorization Bypass Through User-Controlled Key. Under specific conditions, an authenticated attacker could cause Duo AI workflow runners to execute under another user's identit [truncated]
GitLab has remediated an authorization bypass vulnerability in GitLab Enterprise Edition (EE) that could allow authenticated users with developer-role permissions to access sensitive deployment data on projects. The issue stems from improper authorization checks (CWE-862) and affects versions from 11.5 through 18.10.6, 18.11.0 through 18.11.3, and 19.0.0. GitLab released patches on May 27, 2026 in version [truncated]
GitLab has remediated a denial-of-service vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE). The issue, assigned CVSS 3.1 score 6.5 (Medium), stems from insufficient validation that could allow an authenticated user to cause denial of service under certain conditions. The vulnerability affects all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1. Git [truncated]
A low-severity vulnerability was discovered in GitLab EE, affecting versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3. The issue allowed an authenticated user with Maintainer permissions to modify or delete project approval rules due to missing authorization checks when instance-level approval rule editing prevention was enabled.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations. This issue has a CVSS score of 2.7 and LOW severity. The vulnerability [truncated]
GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization. This issue has a CVSS score of 5.4 and is considered Medium severity. Users of [truncated]
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization. This issue has a CVSS score of 4.3, indicating a medium severity. The vulnerability all [truncated]
CVE-2021-22175 is a GitLab server-side request forgery (SSRF) vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. That KEV listing means organizations using GitLab should treat this as a priority remediation item and follow the vendor’s mitigation guidance as soon as possible. The supplied source corpus does not include version ranges, exploitation details, or impact specific [truncated]
CVE-2021-39935 is a server-side request forgery (SSRF) vulnerability affecting GitLab Community and Enterprise Editions. CISA lists it in the Known Exploited Vulnerabilities catalog, so defenders should treat it as actively exploited and prioritize remediation. The supplied corpus does not include affected version ranges or CVSS scoring, so version-specific exposure should be confirmed against the officia [truncated]
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown. This vulnerability has been addressed in the latest GitLab releases. Users are advised to update to the patched versions to prevent potential e [truncated]
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage. This issue has been patched in GitLab versions 18.6.3 and 18.7.1. Users of affected versions s [truncated]
CVE-2023-7028 is a GitLab Community and Enterprise Editions improper access control vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-05-01. Because it is listed in KEV, defenders should treat it as an urgent patch-or-mitigate issue for any GitLab CE/EE deployment, especially externally reachable instances. CISA’s guidance is to apply vendor mitigations or discontinue us [truncated]
CVE-2021-22205 is a GitLab Community and Enterprise Editions remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because CISA also marks the issue as having known ransomware campaign use, it should be treated as an immediate patching priority for any affected GitLab deployment.
CVE-2016-4340 describes a GitLab impersonation issue in which a remote authenticated user could "log in" as another user through unspecified vectors. NVD rates the issue HIGH (CVSS 3.0 8.8) with network attack scope, low complexity, and no user interaction. The affected range in the NVD corpus spans GitLab 8.2.0 through 8.7.0. Because the issue enables account impersonation, it should be treated as a high [truncated]