Gitlab
Gitlab
See the latest tracked release, confirm when it was published, and subscribe for update emails.
16.11.10
- Release date
- September 17, 2024
- Security status
- 18 high-severity CVEs tracked in the last 90 days. Current version not affected.
Source
Public release notes are linked for the latest stored release.
Release history
See the latest published releases stored for this product.
| Version | Published | Notes |
|---|---|---|
| 16.11.10 | 2024-09-17 | Release Notes |
Vulnerability tracking
versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.
Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.
| CVE | Severity | Published | Status | Summary |
|---|---|---|---|---|
| CVE-2026-6896 | HIGH (8.7) | 2026-07-08 | Current versionnot affected | GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input. Affected versions
Show 1 more
|
| CVE-2026-13320 | HIGH (7.3) | 2026-07-08 | Current versionnot affected | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input. Affected versions
Show 1 more
|
| CVE-2026-12053 | HIGH (8.6) | 2026-06-25 | Current versionnot affected | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows. Affected versions
|
| CVE-2026-10712 | HIGH (8.0) | 2026-06-25 | Current versionnot affected | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions. Affected versions
|
| CVE-2026-10086 | HIGH (8.7) | 2026-06-25 | Current versionnot affected | GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in the context of another user's session, due to improper sanitization of user-supplied input. Affected versions
|
| CVE-2026-8589 | HIGH (8.7) | 2026-06-11 | Current versionnot affected | GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to add unauthorized email addresses to a targeted user's account due to improper sanitization of user-supplied input in certain group setting fields. Affected versions
Show 1 more
|
| CVE-2026-7250 | HIGH (7.5) | 2026-06-11 | Current versionnot affected | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsing middleware. Affected versions
Show 1 more
|
| CVE-2026-6552 | HIGH (8.7) | 2026-06-11 | Current versionnot affected | GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with group Owner role to take over another group member's GitLab account due to improper authorization in the Group SAML identity management functionality. Affected versions
Show 1 more
|
| CVE-2026-10087 | HIGH (8.7) | 2026-06-11 | Current versionnot affected | GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code on behalf of a targeted user due to improper input sanitization in the Analytics Dashboard. Affected versions
Show 1 more
|
| CVE-2026-4868 | HIGH (8.2) | 2026-05-27 | Current versionnot affected | GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authenticated user to cause specific Duo AI workflows to run under another user's identity due to improper user identity resolution when triggering Duo AI workflow runners. Affected versions
|
| CVE-2026-7481 | HIGH (8.7) | 2026-05-14 | Current versionnot affected | GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to execute arbitrary JavaScript in other users' browsers due to improper input sanitization. Affected versions
Show 1 more
|
| CVE-2026-7377 | HIGH (8.7) | 2026-05-14 | Current versionnot affected | GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization. Affected versions
Show 1 more
|
| CVE-2026-6073 | HIGH (8.7) | 2026-05-14 | Current versionnot affected | GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to execute arbitrary JavaScript in other users' browsers due to improper input sanitization. Affected versions
Show 1 more
|
| CVE-2026-1659 | HIGH (7.5) | 2026-05-14 | Current versionnot affected | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted requests due to insufficient input validation. Affected versions
Show 1 more
|
| CVE-2026-1322 | HIGH (8.1) | 2026-05-14 | Current versionnot affected | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with a read_api scoped OAuth application to create issues and add comments to issues in private projects due to improper authorization. Affected versions
Show 1 more
|
| CVE-2026-1184 | HIGH (7.5) | 2026-05-14 | Current versionnot affected | GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by uploading a specially crafted file due to improper validation. Affected versions
Show 1 more
|
| CVE-2025-14870 | HIGH (7.5) | 2026-05-14 | Current versionnot affected | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted JSON payloads due to insufficient input validation. Affected versions
Show 1 more
|
| CVE-2025-14869 | HIGH (7.5) | 2026-05-14 | Current versionnot affected | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted payloads on certain API endpoints. Affected versions
Show 1 more
|