Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

GitLab

Vulnerabilities in GitLab Community and Enterprise Edition — the DevOps platform that, when compromised, can expose an organization's entire source code history and CI/CD pipeline secrets.

6 CVEs4 articlesRSS
CVEs
CVE-2026-10053
[ HIGH ]CVSS 8.5EPSS 0.8%patched

GitLab CE/EE authenticated RCE via path traversal in package registry

GitLab CE/EE 18.8 through 19.2 allow an authenticated user to achieve RCE via path traversal in the package registry. Fixed in 19.0.6, 19.1.4, 19.2.2.

GitLab / GitLab CE/EE (self-managed, versions 18.8 – 19.2)
CVE-2026-19478
[ CRITICAL ]CVSS 9.4EPSS 5.8%patched

GitLab GraphQL unauthenticated project deletion and modification

Critical GraphQL flaw in GitLab CE/EE lets unauthenticated attackers modify or delete public projects and user data. Patched; self-hosted instances need manual update.

GitLab / GitLab Community Edition and Enterprise Edition
CVE-2021-22175
[ MEDIUM ]CVSS 6.8EPSS 53.4%kev

GitLab Server-Side Request Forgery (SSRF) Vulnerability

GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.

GitLab / GitLab
CVE-2021-39935
[ MEDIUM ]CVSS 6.8EPSS 35.6%kev

GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.

GitLab / Community and Enterprise Editions
CVE-2023-7028
[ CRITICAL ]CVSS 10.0EPSS 94.6%kev

GitLab Community and Enterprise Editions Improper Access Control Vulnerability

GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.

GitLab / GitLab CE/EE
CVE-2021-22205
[ CRITICAL ]CVSS 9.9EPSS 99.7%kev

GitLab CE/EE ExifTool Remote Code Execution

An improper-validation vulnerability in GitLab Community Edition and Enterprise Edition allows an unauthenticated attacker to achieve remote code execution by uploading a crafted image file processed through a vulnerable ExifTool image-metadata parser.

GitLab / GitLab CE/EE
Articles