<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — GitLab</title><description>Vulnerabilities in GitLab Community and Enterprise Edition — the DevOps platform that, when compromised, can expose an organization&apos;s entire source code history and CI/CD pipeline secrets. Combined article + CVE feed for the GitLab beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2021-22175 — GitLab Server-Side Request Forgery (SSRF) Vulnerability</title><link>https://0daynews.com/cve/cve-2021-22175/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-22175/</guid><description>GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>GitLab</category><category>medium</category><category>cve</category></item><item><title>CVE-2021-22205 — GitLab CE/EE ExifTool Remote Code Execution</title><link>https://0daynews.com/cve/cve-2021-22205/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-22205/</guid><description>An improper-validation vulnerability in GitLab Community Edition and Enterprise Edition allows an unauthenticated attacker to achieve remote code execution by uploading a crafted image file processed through a vulnerable ExifTool image-metadata parser.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>GitLab</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-39935 — GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability</title><link>https://0daynews.com/cve/cve-2021-39935/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-39935/</guid><description>GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API. </description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>GitLab</category><category>medium</category><category>cve</category></item><item><title>CVE-2023-7028 — GitLab Community and Enterprise Editions Improper Access Control Vulnerability</title><link>https://0daynews.com/cve/cve-2023-7028/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-7028/</guid><description>GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>GitLab</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-10053 — GitLab CE/EE authenticated RCE via path traversal in package registry</title><link>https://0daynews.com/cve/cve-2026-10053/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-10053/</guid><description>GitLab CE/EE 18.8 through 19.2 allow an authenticated user to achieve RCE via path traversal in the package registry. Fixed in 19.0.6, 19.1.4, 19.2.2.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>GitLab</category><category>high</category><category>cve</category></item><item><title>CVE-2026-19478 — GitLab GraphQL unauthenticated project deletion and modification</title><link>https://0daynews.com/cve/cve-2026-19478/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-19478/</guid><description>Critical GraphQL flaw in GitLab CE/EE lets unauthenticated attackers modify or delete public projects and user data. Patched; self-hosted instances need manual update.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>GitLab</category><category>critical</category><category>cve</category></item><item><title>GitLab Patches RCE in Package Registry (CVE-2026-10053)</title><link>https://0daynews.com/articles/2026-08-24-gitlab-cve-2026-10053-rce-package-registry/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-24-gitlab-cve-2026-10053-rce-package-registry/</guid><description>GitLab CE/EE authenticated RCE via path traversal in the package registry affects 18.8 through 19.2. Upgrade to 19.0.6, 19.1.4, or 19.2.2 now.</description><pubDate>Mon, 24 Aug 2026 06:00:00 GMT</pubDate><category>GitLab</category><category>article</category></item><item><title>Critical GitLab Flaw Lets Attackers Delete Projects</title><link>https://0daynews.com/articles/2026-08-17-gitlab-cve-2026-19478-graphql-unauth/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-17-gitlab-cve-2026-19478-graphql-unauth/</guid><description>GitLab patched CVE-2026-19478 (CVSS 9.4): unauthenticated attackers can delete or modify public projects. Self-hosted instances need immediate manual update.</description><pubDate>Mon, 17 Aug 2026 22:00:00 GMT</pubDate><category>GitLab</category><category>article</category></item><item><title>GitLab RCE PoC Published: No Admin Rights Required</title><link>https://0daynews.com/articles/2026-07-25-gitlab-18-11-3-rce-poc-published/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-25-gitlab-18-11-3-rce-poc-published/</guid><description>A working RCE exploit for self-managed GitLab 18.11.3 is now public. Any authenticated user can execute server commands as git — no admin rights needed.</description><pubDate>Sat, 25 Jul 2026 10:00:00 GMT</pubDate><category>GitLab</category><category>article</category></item><item><title>GitLab&apos;s ExifTool RCE Sat Unrecognized for Months</title><link>https://0daynews.com/articles/2026-07-06-gitlab-exiftool-rce-cve-2021-22205/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-06-gitlab-exiftool-rce-cve-2021-22205/</guid><description>CVE-2021-22205 was quietly fixed in April 2021 — but its full unauthenticated remote-code-execution severity wasn&apos;t widely understood until late 2021, by which point mass exploitation had already begun.</description><pubDate>Mon, 06 Jul 2026 13:00:00 GMT</pubDate><category>GitLab</category><category>article</category></item></channel></rss>