Back to search

Gitlab

Gitlab

See the latest tracked release, confirm when it was published, and subscribe for update emails.

Current version EOL
Last checked: 2026-09-04

16.11.10

Release date
September 17, 2024
Security status
Current version appears affected by 63 high-severity CVEs.

Source

GitLab Docs

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
16.11.10 2024-09-17 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-18252 HIGH (7.3) 2026-08-26 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.

Affected versions
  • From (including) 18.9 - Up to (excluding) 19.1.7
  • From (including) 19.2 - Up to (excluding) 19.2.5
Show 1 more
  • From (including) 19.3 - Up to (excluding) 19.3.1
CVE-2026-10053 HIGH (8.5) 2026-08-23 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.

Affected versions
  • From (including) 18.8 - Up to (excluding) 19.0.6
  • From (including) 19.1 - Up to (excluding) 19.1.4
Show 1 more
  • From (including) 19.2 - Up to (excluding) 19.2.2
CVE-2026-19650 HIGH (7.1) 2026-08-17 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.

Affected versions
  • From (including) 18.2 - Up to (excluding) 18.11.11
  • From (including) 19.0 - Up to (excluding) 19.0.8
Show 2 more
  • From (including) 19.1 - Up to (excluding) 19.1.6
  • From (including) 19.2 - Up to (excluding) 19.2.4
CVE-2026-19478 CRITICAL (9.4) 2026-08-17 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Affected versions
  • From (including) 18.2 - Up to (excluding) 18.11.11
  • From (including) 19.0 - Up to (excluding) 19.0.8
Show 2 more
  • From (including) 19.1 - Up to (excluding) 19.1.6
  • From (including) 19.2 - Up to (excluding) 19.2.4
CVE-2026-15217 HIGH (8.7) 2026-08-12 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled values rendered in table cell content by an analytics dashboard component.

Affected versions
  • From (including) 18.2 - Up to (excluding) 19.0.6
  • From (including) 19.1 - Up to (excluding) 19.1.4
Show 1 more
  • From (including) 19.2 - Up to (excluding) 19.2.2
CVE-2026-15216 HIGH (8.7) 2026-08-12 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled data rendered in pagination controls by an analytics dashboard component.

Affected versions
  • From (including) 18.2 - Up to (excluding) 19.0.6
  • From (including) 19.1 - Up to (excluding) 19.1.4
Show 1 more
  • From (including) 19.2 - Up to (excluding) 19.2.2
CVE-2026-16494 HIGH (7.1) 2026-08-12 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization checks on a project update endpoint.

Affected versions
  • From (including) 19.1 - Up to (excluding) 19.1.4
  • From (including) 19.2 - Up to (excluding) 19.2.2
CVE-2026-19228 HIGH (8.5) 2026-08-12 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of identity information supplied in requests.

Affected versions
  • From (including) 19.1 - Up to (excluding) 19.1.4
  • From (including) 19.2 - Up to (excluding) 19.2.2
CVE-2026-15423 HIGH (8.5) 2026-08-12 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute CI/CD pipelines on a protected branch without the required push permissions due to improper authorization in pipeline reference validation.

Affected versions
  • From (including) 19.0 - Up to (excluding) 19.0.6
  • From (including) 19.1 - Up to (excluding) 19.1.4
Show 1 more
  • From (including) 19.2 - Up to (excluding) 19.2.2
CVE-2026-16627 HIGH (7.7) 2026-08-12 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate privileges due to improper sanitization of HTML content rendered in a CI job modal.

Affected versions
  • From (including) 19.2 - Up to (excluding) 19.2.2
CVE-2026-6267 HIGH (8.5) 2026-07-29 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.

Affected versions
  • From (including) 10.1.0 - Up to (excluding) 19.0.5
  • From (including) 19.1 - Up to (excluding) 19.1.3
Show 1 more
  • From (including) 19.2 - Up to (excluding) 19.2.1
CVE-2026-12436 HIGH (8.4) 2026-07-29 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes when processing pipeline schedule inputs.

Affected versions
  • From (including) 18.0 - Up to (excluding) 19.0.5
  • From (including) 19.1 - Up to (excluding) 19.1.3
Show 1 more
  • From (including) 19.2 - Up to (excluding) 19.2.1
CVE-2026-15975 HIGH (7.5) 2026-07-29 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions.

Affected versions
  • From (including) 11.8 - Up to (excluding) 19.0.5
  • From (including) 19.1 - Up to (excluding) 19.1.3
Show 1 more
  • From (including) 19.2 - Up to (excluding) 19.2.1
CVE-2026-6896 HIGH (8.7) 2026-07-08 Current versionaffected

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.

Affected versions
  • From (including) 13.11 - Up to (excluding) 18.11.7
  • From (including) 19.0 - Up to (excluding) 19.0.4
Show 1 more
  • From (including) 19.1 - Up to (excluding) 19.1.2
CVE-2026-13320 HIGH (7.3) 2026-07-08 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.

Affected versions
  • From (including) 15.7 - Up to (excluding) 18.11.7
  • From (including) 19.0 - Up to (excluding) 19.0.4
Show 1 more
  • From (including) 19.1 - Up to (excluding) 19.1.2
CVE-2026-10086 HIGH (8.7) 2026-06-25 Current versionaffected

GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in the context of another user's session, due to improper sanitization of user-supplied input.

Affected versions
  • From (including) 16.4 - Up to (excluding) 18.11.6
  • From (including) 19.0 - Up to (excluding) 19.0.3
Show 1 more
  • From (including) 19.1 - Up to (excluding) 19.1.1
CVE-2026-10712 HIGH (8.0) 2026-06-25 Current versionnot affected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions.

Affected versions
  • From (including) 18.10 - Up to (excluding) 18.11.6
  • From (including) 19.0 - Up to (excluding) 19.0.3
Show 1 more
  • From (including) 19.1 - Up to (excluding) 19.1.1
CVE-2026-12053 HIGH (8.6) 2026-06-25 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows.

Affected versions
  • From (including) 19.1 - Up to (excluding) 19.1.1
CVE-2026-7250 HIGH (7.5) 2026-06-11 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsing middleware.

Affected versions
  • From (including) 12.10 - Up to (excluding) 18.10.8
  • From (including) 18.11 - Up to (excluding) 18.11.5
Show 1 more
  • From (including) 19.0 - Up to (excluding) 19.0.2
CVE-2026-8589 HIGH (7.3) 2026-06-11 Current versionaffected

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to add unauthorized email addresses to a targeted user's account due to improper sanitization of user-supplied input in certain group setting fields.

Affected versions
  • From (including) 13.1.4 - Up to (excluding) 18.10.8
  • From (including) 18.11 - Up to (excluding) 18.11.5
Show 1 more
  • From (including) 19.0 - Up to (excluding) 19.0.2
CVE-2026-10087 HIGH (8.7) 2026-06-11 Current versionnot affected

GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code on behalf of a targeted user due to improper input sanitization in the Analytics Dashboard.

Affected versions
  • From (including) 17.1 - Up to (excluding) 18.10.8
  • From (including) 18.11 - Up to (excluding) 18.11.5
Show 1 more
  • From (including) 19.0 - Up to (excluding) 19.0.2
CVE-2026-1659 HIGH (7.5) 2026-05-14 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted requests due to insufficient input validation.

Affected versions
  • From (including) 9.0 - Up to (excluding) 18.9.7
  • From (including) 18.10 - Up to (excluding) 18.10.6
Show 1 more
  • From (including) 18.11 - Up to (excluding) 18.11.3
CVE-2026-7481 HIGH (8.7) 2026-05-14 Current versionaffected

GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to execute arbitrary JavaScript in other users' browsers due to improper input sanitization.

Affected versions
  • From (including) 16.4 - Up to (excluding) 18.9.7
  • From (including) 18.10 - Up to (excluding) 18.10.6
Show 1 more
  • From (including) 18.11 - Up to (excluding) 18.11.3
CVE-2026-5262 HIGH (8.0) 2026-04-22 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation.

Affected versions
  • From (including) 16.1.0 - Up to (excluding) 18.9.6
  • From (including) 18.10 - Up to (excluding) 18.10.4
Show 1 more
  • From (including) 18.11 - Up to (excluding) 18.11.1
CVE-2025-12664 HIGH (7.5) 2026-04-08 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.

Affected versions
  • From (including) 13.0 - Up to (excluding) 18.8.9
  • From (including) 18.9 - Up to (excluding) 18.9.5
Show 1 more
  • From (including) 18.10 - Up to (excluding) 18.10.3
CVE-2026-1092 HIGH (7.5) 2026-04-08 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service due to improper input validation of JSON payloads.

Affected versions
  • From (including) 12.10 - Up to (excluding) 18.8.9
  • From (including) 18.9 - Up to (excluding) 18.9.5
Show 1 more
  • From (including) 18.10 - Up to (excluding) 18.10.3
CVE-2026-5173 HIGH (8.5) 2026-04-08 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control.

Affected versions
  • From (including) 16.9.6 - Up to (excluding) 18.8.9
  • From (including) 18.9 - Up to (excluding) 18.9.5
Show 1 more
  • From (including) 18.10 - Up to (excluding) 18.10.3
CVE-2026-2370 HIGH (8.1) 2026-03-29 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with minimal workspace permissions to obtain installation credentials and impersonate the GitLab app due to improper authorization checks.

Affected versions
  • From (including) 14.3 - Up to (excluding) 18.8.7
  • From (including) 18.9 - Up to (excluding) 18.9.3
Show 1 more
  • From (including) 18.10 - Up to (excluding) 18.10.1
CVE-2026-2995 HIGH (7.7) 2026-03-25 Current versionaffected

GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to add email addresses to targeted user accounts due to improper sanitization of HTML content.

Affected versions
  • From (including) 15.4 - Up to (excluding) 18.8.7
  • From (including) 18.9 - Up to (excluding) 18.9.3
Show 1 more
  • From (including) 18.10 - Up to (excluding) 18.10.1
CVE-2025-13929 HIGH (7.5) 2026-03-11 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by issuing specially crafted requests to repository archive endpoints under certain conditions.

Affected versions
  • From (including) 10.0 - Up to (excluding) 18.7.6
  • From (including) 18.8 - Up to (excluding) 18.8.6
Show 1 more
  • From (including) 18.9 - Up to (excluding) 18.9.2
CVE-2025-14513 HIGH (7.5) 2026-03-11 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially crafted JSON payloads in the protected branches API.

Affected versions
  • From (including) 16.11 - Up to (excluding) 18.7.6
  • From (including) 18.8 - Up to (excluding) 18.8.6
Show 1 more
  • From (including) 18.9 - Up to (excluding) 18.9.2
CVE-2026-1090 HIGH (8.7) 2026-03-11 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inject JavaScript in a browser due to improper sanitization of placeholder content in markdown processing.

Affected versions
  • From (including) 10.6 - Up to (excluding) 18.7.6
  • From (including) 18.8 - Up to (excluding) 18.8.6
Show 1 more
  • From (including) 18.9 - Up to (excluding) 18.9.2
CVE-2025-14511 HIGH (7.5) 2026-02-25 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted files to the container registry event endpoint under certain conditions.

Affected versions
  • From (including) 12.2 - Up to (excluding) 18.7.5
  • From (including) 18.8 - Up to (excluding) 18.8.5
Show 1 more
  • From (including) 18.9 - Up to (excluding) 18.9.1
CVE-2026-0752 HIGH (8.0) 2026-02-25 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that under certain circumstances, could have allowed an unauthenticated user to inject arbitrary scripts into the Mermaid sandbox UI.

Affected versions
  • From (including) 16.2 - Up to (excluding) 18.7.5
  • From (including) 18.8 - Up to (excluding) 18.8.5
Show 1 more
  • From (including) 18.9 - Up to (excluding) 18.9.1
CVE-2026-1388 HIGH (7.5) 2026-02-25 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause regular expression denial of service by sending specially crafted input to a merge request endpoint under certain conditions.

Affected versions
  • From (including) 9.2 - Up to (excluding) 18.7.5
  • From (including) 18.8 - Up to (excluding) 18.8.5
Show 1 more
  • From (including) 18.9 - Up to (excluding) 18.9.1
CVE-2026-1662 HIGH (7.5) 2026-02-25 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause Denial of Service by sending specially crafted requests to the Jira events endpoint.

Affected versions
  • From (including) 14.4 - Up to (excluding) 18.7.5
  • From (including) 18.8 - Up to (excluding) 18.8.5
Show 1 more
  • From (including) 18.9 - Up to (excluding) 18.9.1
CVE-2025-8099 HIGH (7.5) 2026-02-11 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.

Affected versions
  • From (including) 10.8 - Up to (excluding) 18.6.6
  • From (including) 18.7 - Up to (excluding) 18.7.4
Show 1 more
  • From (including) 18.8 - Up to (excluding) 18.8.4
CVE-2026-0595 HIGH (7.3) 2026-02-11 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to add unauthorized email addresses to victim accounts through HTML injection in test case titles.

Affected versions
  • From (including) 13.9 - Up to (excluding) 18.6.6
  • From (including) 18.7 - Up to (excluding) 18.7.4
Show 1 more
  • From (including) 18.8 - Up to (excluding) 18.8.4
CVE-2025-13927 HIGH (7.5) 2026-01-22 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted requests with malformed authentication data.

Affected versions
  • From (including) 11.9 - Up to (excluding) 18.6.4
  • From (including) 18.7 - Up to (excluding) 18.7.2
Show 1 more
  • From (including) 18.8 - Up to (excluding) 18.8.2
CVE-2025-11224 HIGH (7.7) 2026-01-14 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to execute stored cross-site scripting through improper input validation in the Kubernetes proxy functionality.

Affected versions
  • From (including) 15.10 - Up to (excluding) 18.3.6
  • From (including) 18.4 - Up to (excluding) 18.4.4
Show 1 more
  • From (including) 18.5 - Up to (excluding) 18.5.2
CVE-2025-12029 HIGH (8.0) 2025-12-11 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI."

Affected versions
  • From (including) 15.11 - Up to (excluding) 18.4.6
  • From (including) 18.5 - Up to (excluding) 18.5.4
Show 1 more
  • From (including) 18.6 - Up to (excluding) 18.6.2
CVE-2025-12562 HIGH (7.5) 2025-12-11 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted GraphQL queries that bypass query complexity limits.

Affected versions
  • From (including) 11.10 - Up to (excluding) 18.4.6
  • From (including) 18.5 - Up to (excluding) 18.5.4
Show 1 more
  • From (including) 18.6 - Up to (excluding) 18.6.2
CVE-2025-11447 HIGH (7.5) 2025-10-27 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending GraphQL requests with crafted JSON payloads.

Affected versions
  • From (including) 11.0 - Up to (excluding) 18.3.5
  • From (including) 18.4 - Up to (excluding) 18.4.3
Show 1 more
  • From (including) 18.5 - Up to (excluding) 18.5.1
CVE-2025-10004 HIGH (7.5) 2025-10-09 Current versionaffected

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.

Affected versions
  • From (including) 13.12 - Up to (excluding) 18.2.8
  • From (including) 18.3 - Up to (excluding) 18.3.4
Show 1 more
  • From (including) 18.4 - Up to (excluding) 18.4.2
CVE-2025-8014 HIGH (7.5) 2025-09-27 Current versionaffected

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.

Affected versions
  • From (including) 11.10 - Up to (excluding) 18.2.7
  • From (including) 18.3 - Up to (excluding) 18.3.3
Show 1 more
  • From (including) 18.4 - Up to (excluding) 18.4.1
CVE-2025-9642 HIGH (8.7) 2025-09-26 Current versionaffected

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover.

Affected versions
  • From (including) 14.10 - Up to (excluding) 18.2.7
  • From (including) 18.3 - Up to (excluding) 18.3.3
Show 1 more
  • From (including) 18.4 - Up to (excluding) 18.4.1
CVE-2025-9958 HIGH (7.7) 2025-09-26 Current versionaffected

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.

Affected versions
  • From (including) 14.10 - Up to (excluding) 18.2.7
  • From (including) 18.3 - Up to (excluding) 18.3.3
Show 1 more
  • From (including) 18.4 - Up to (excluding) 18.4.1
CVE-2025-10858 HIGH (7.5) 2025-09-26 Current versionaffected

An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that allows unauthenticated users to cause a Denial of Service (DoS) condition while uploading specifically crafted large JSON files.

Affected versions
  • From (including) 0 - Up to (excluding) 18.2.7
  • From (including) 18.3 - Up to (excluding) 18.3.3
Show 1 more
  • From (including) 18.4 - Up to (excluding) 18.4.1
CVE-2025-2256 HIGH (7.5) 2025-09-12 Current versionaffected

An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.

Affected versions
  • From (including) 7.12 - Up to (excluding) 18.1.6
  • From (including) 18.2 - Up to (excluding) 18.2.6
Show 1 more
  • From (including) 18.3 - Up to (excluding) 18.3.2
CVE-2025-6454 HIGH (8.5) 2025-09-12 Current versionaffected

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to make unintended internal requests through proxy environments by injecting crafted sequences.

Affected versions
  • From (including) 16.11 - Up to (excluding) 18.1.6
  • From (including) 18.2 - Up to (excluding) 18.2.6
Show 1 more
  • From (including) 18.3 - Up to (excluding) 18.3.2
CVE-2025-7734 HIGH (8.7) 2025-08-13 Current versionaffected

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

Affected versions
  • From (including) 14.2 - Up to (excluding) 18.0.6
  • From (including) 18.1 - Up to (excluding) 18.1.4
Show 1 more
  • From (including) 18.2 - Up to (excluding) 18.2.2
CVE-2025-4439 HIGH (7.7) 2025-07-23 Current versionaffected

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks.

Affected versions
  • From (including) 15.10 - Up to (excluding) 18.0.5
  • From (including) 18.1 - Up to (excluding) 18.1.3
Show 1 more
  • From (including) 18.2 - Up to (excluding) 18.2.1
CVE-2025-4700 HIGH (8.7) 2025-07-23 Current versionaffected

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to XSS.

Affected versions
  • From (including) 15.10 - Up to (excluding) 18.0.5
  • From (including) 18.1 - Up to (excluding) 18.1.3
Show 1 more
  • From (including) 18.2 - Up to (excluding) 18.2.1
CVE-2025-2443 HIGH (8.7) 2025-06-20 Current versionaffected

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

Affected versions
  • From (including) 16.6 - Up to (excluding) 17.9.7
  • From (including) 17.10 - Up to (excluding) 17.10.5
Show 1 more
  • From (including) 17.11 - Up to (excluding) 17.11.1
CVE-2025-1763 HIGH (8.7) 2025-05-30 Current versionaffected

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

Affected versions
  • From (including) 16.6 - Up to (excluding) 17.9.7
  • From (including) 17.10 - Up to (excluding) 17.10.5
Show 1 more
  • From (including) 17.11 - Up to (excluding) 17.11.1
CVE-2025-0993 HIGH (7.5) 2025-05-22 Current versionaffected

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.

Affected versions
  • From (including) 0 - Up to (excluding) 17.10.7
  • From (including) 17.11 - Up to (excluding) 17.11.3
Show 1 more
  • From (including) 18.0 - Up to (excluding) 18.0.1
CVE-2025-1908 HIGH (7.7) 2025-04-24 Current versionaffected

An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

Affected versions
  • From (including) 16.6 - Up to (excluding) 17.9.7
  • From (including) 17.10 - Up to (excluding) 17.10.5
Show 1 more
  • From (including) 17.11 - Up to (excluding) 17.11.1
CVE-2025-2255 HIGH (8.7) 2025-03-27 Current versionaffected

An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.

Affected versions
  • From (including) 13.5.0 - Up to (excluding) 17.8.6
  • From (including) 17.9 - Up to (excluding) 17.9.3
Show 1 more
  • From (including) 17.10 - Up to (excluding) 17.10.1
CVE-2025-0555 HIGH (7.7) 2025-03-03 Current versionaffected

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.

Affected versions
  • From (including) 16.6 - Up to (excluding) 17.7.6
  • From (including) 17.8 - Up to (excluding) 17.8.4
Show 1 more
  • From (including) 17.9 - Up to (excluding) 17.9.1
CVE-2025-0475 HIGH (8.7) 2025-03-03 Current versionaffected

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.

Affected versions
  • From (including) 15.10 - Up to (excluding) 17.7.6
  • From (including) 17.8 - Up to (excluding) 17.8.4
Show 1 more
  • From (including) 17.9 - Up to (excluding) 17.9.1
CVE-2024-7102 CRITICAL (9.6) 2025-02-13 Current versionaffected

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.

Affected versions
  • From (including) 16.4 - Up to (excluding) 17.5.0
CVE-2025-0376 HIGH (8.7) 2025-02-12 Current versionaffected

An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions via a change page.

Affected versions
  • From (including) 13.3 - Up to (excluding) 17.6.5
  • From (including) 17.7 - Up to (excluding) 17.7.4
Show 1 more
  • From (including) 17.8 - Up to (excluding) 17.8.2
CVE-2024-9631 HIGH (7.5) 2025-02-05 Current versionaffected

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.

Affected versions
  • From (including) 13.6 - Up to (excluding) 17.2.9
  • From (including) 17.3 - Up to (excluding) 17.3.5
Show 1 more
  • From (including) 17.4 - Up to (excluding) 17.4.2
CVE-2024-8233 HIGH (7.5) 2024-12-12 Current versionaffected

An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could cause a denial of service with requests for diff files on a commit or merge request.

Affected versions
  • From (including) 9.4 - Up to (excluding) 17.4.6
  • From (including) 17.5 - Up to (excluding) 17.5.4
Show 1 more
  • From (including) 17.6 - Up to (excluding) 17.6.2
CVE-2024-11274 HIGH (8.7) 2024-12-12 Current versionaffected

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.

Affected versions
  • From (including) 16.1 - Up to (excluding) 17.4.6
  • From (including) 17.5 - Up to (excluding) 17.5.4
Show 1 more
  • From (including) 17.6 - Up to (excluding) 17.6.2
CVE-2024-8114 HIGH (8.2) 2024-11-26 Current versionaffected

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.

Affected versions
  • From (including) 8.12 - Up to (excluding) 17.4.5
  • From (including) 17.5 - Up to (excluding) 17.5.3
Show 1 more
  • From (including) 17.6 - Up to (excluding) 17.6.1
CVE-2024-9693 HIGH (8.5) 2024-11-14 Current versionaffected

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific configurations.

Affected versions
  • From (including) 16.0 - Up to (excluding) 17.3.7
  • From (including) 17.4.0 - Up to (excluding) 17.4.4
Show 1 more
  • From (including) 17.5.0 - Up to (excluding) 17.5.2
CVE-2024-8312 HIGH (8.7) 2024-10-24 Current versionaffected

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.

Affected versions
  • From (including) 15.10 - Up to (excluding) 17.3.6
  • From (including) 17.4 - Up to (excluding) 17.4.3
Show 1 more
  • From (including) 17.5 - Up to (excluding) 17.5.1
CVE-2024-8970 HIGH (8.2) 2024-10-11 Current versionaffected

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

Affected versions
  • From (including) 11.6 - Up to (excluding) 17.2.9
  • From (including) 17.3 - Up to (excluding) 17.3.5
Show 1 more
  • From (including) 17.4 - Up to (excluding) 17.4.2
CVE-2024-9164 CRITICAL (9.6) 2024-10-11 Current versionaffected

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.

Affected versions
  • From (including) 12.5 - Up to (excluding) 17.2.9
  • From (including) 17.3 - Up to (excluding) 17.3.5
Show 1 more
  • From (including) 17.4 - Up to (excluding) 17.4.2
CVE-2024-8977 HIGH (8.2) 2024-10-10 Current versionaffected

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.

Affected versions
  • From (including) 15.10 - Up to (excluding) 17.2.9
  • From (including) 17.3 - Up to (excluding) 17.3.5
Show 1 more
  • From (including) 17.4 - Up to (excluding) 17.4.2
CVE-2024-6678 CRITICAL (9.9) 2024-09-12 Current versionaffected

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances.

Affected versions
  • From (including) 8.14 - Up to (excluding) 17.1.7
  • From (including) 17.2 - Up to (excluding) 17.2.5
Show 1 more
  • From (including) 17.3 - Up to (excluding) 17.3.2
CVE-2024-8635 HIGH (7.7) 2024-09-12 Current versionaffected

A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It was possible for an attacker to make requests to internal resources using a custom Maven Dependency Proxy URL

Affected versions
  • From (including) 16.8 - Up to (excluding) 17.1.7
  • From (including) 17.2 - Up to (excluding) 17.2.5
Show 1 more
  • From (including) 17.3 - Up to (excluding) 17.3.2
CVE-2024-8124 HIGH (7.5) 2024-09-12 Current versionaffected

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a specific POST request.

Affected versions
  • From (including) 16.4 - Up to (excluding) 17.1.7
  • From (including) 17.2 - Up to (excluding) 17.2.5
Show 1 more
  • From (including) 17.3 - Up to (excluding) 17.3.2
CVE-2024-8640 HIGH (8.5) 2024-09-12 Current versionaffected

An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject commands into a connected Cube server.

Affected versions
  • From (including) 16.11 - Up to (excluding) 17.1.7
  • From (including) 17.2 - Up to (excluding) 17.2.5
Show 1 more
  • From (including) 17.3 - Up to (excluding) 17.3.2
CVE-2024-7047 HIGH (7.7) 2024-07-25 Current versionaffected

A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user.

Affected versions
  • From (including) 16.6 - Up to (excluding) 17.0.5
  • From (including) 17.1 - Up to (excluding) 17.1.3
Show 1 more
  • From (including) 17.2 - Up to (excluding) 17.2.1
CVE-2024-4835 HIGH (8.0) 2024-05-23 Current versionaffected

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

Affected versions
  • From (including) 15.11 - Up to (excluding) 16.10.6
  • From (including) 16.11 - Up to (excluding) 16.11.3
Show 2 more
  • From (including) 17.0 - Up to (excluding) 17.0.1
  • From (including) 15.11 - Up to (excluding) 17.0.1