GitLab
Vulnerabilities in GitLab Community and Enterprise Edition — the DevOps platform that, when compromised, can expose an organization's entire source code history and CI/CD pipeline secrets.
GitLab CE/EE authenticated RCE via path traversal in package registry
GitLab CE/EE 18.8 through 19.2 allow an authenticated user to achieve RCE via path traversal in the package registry. Fixed in 19.0.6, 19.1.4, 19.2.2.
GitLab GraphQL unauthenticated project deletion and modification
Critical GraphQL flaw in GitLab CE/EE lets unauthenticated attackers modify or delete public projects and user data. Patched; self-hosted instances need manual update.
GitLab Server-Side Request Forgery (SSRF) Vulnerability
GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.
GitLab Community and Enterprise Editions Improper Access Control Vulnerability
GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.
GitLab CE/EE ExifTool Remote Code Execution
An improper-validation vulnerability in GitLab Community Edition and Enterprise Edition allows an unauthenticated attacker to achieve remote code execution by uploading a crafted image file processed through a vulnerable ExifTool image-metadata parser.

GitLab Patches RCE in Package Registry (CVE-2026-10053)
GitLab CE/EE authenticated RCE via path traversal in the package registry affects 18.8 through 19.2. Upgrade to 19.0.6, 19.1.4, or 19.2.2 now.

Critical GitLab Flaw Lets Attackers Delete Projects
GitLab patched CVE-2026-19478 (CVSS 9.4): unauthenticated attackers can delete or modify public projects. Self-hosted instances need immediate manual update.

GitLab RCE PoC Published: No Admin Rights Required
A working RCE exploit for self-managed GitLab 18.11.3 is now public. Any authenticated user can execute server commands as git — no admin rights needed.

GitLab's ExifTool RCE Sat Unrecognized for Months
CVE-2021-22205 was quietly fixed in April 2021 — but its full unauthenticated remote-code-execution severity wasn't widely understood until late 2021, by which point mass exploitation had already begun.