Where
AND
-Infinity
0
Severity
8.8
SSRF
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send requests from the GitLab server to unintended services.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.8.2, 17.7.4, 17.6.5 or above.
First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site scripting.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.6.4, 17.7.3, 17.8.1 or above.
First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions via a change page.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.6.5, 17.7.4, 17.8.2 or above.
First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.7.6, 17.8.4, 17.9.1 or above.
First published (updated )
Severity
7.7
XSS
AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a user’s browser under specific conditions. This is a high severity issue (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N, 7.7). It is now mitigated in the latest release and is assigned CVE-2025-0555.

1 / 2
Source: GitLab

Remedy

Upgrade to versions 17.7.6, 17.8.4, 17.9.1 or above.
First published (updated )
Severity
7.5
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

An improper access control vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows a user with a custom permission to view contents of a repository even if that access is not authorized. This is a low severity issue (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N, 2.7). It is now mitigated in the latest release and is assigned CVE-2025-1042.

1 / 2
Source: GitLab

Remedy

Upgrade to versions 17.6.5, 17.7.4, 17.8.2 or above.
First published (updated )
Severity
7.5
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

An information disclosure vulnerability in GitLab CE/EE affecting all versions from 8.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send a crafted request to a backend server to reveal sensitive information.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.6.5, 17.7.4, 17.8.2 or above.
First published (updated )
Severity
7.5
AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository mirroring settings could potentially expose sensitive authentication information.

1 / 2
Source: MITRE

Remedy

Upgrade to version 17.9.2, 17.8.5, 17.7.7
First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs.

1 / 2
Source: MITRE

Remedy

Upgrade to version 17.9.2, 17.8.5, 17.7.7 or above.
First published (updated )
Severity
7.4
Command Injection, Input Validation
AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N

An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.7.7, 17.8.5, 17.9.2.
First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.

1 / 2
Source: MITRE

Remedy

Upgrade to version 17.6.5, 17.7.4 or 17.8.2
First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of service vulnerability could allow an attacker to cause a system reboot under certain conditions.

1 / 2
Source: MITRE

Remedy

Upgrade to version 17.9.2, 17.8.5, 17.7.7
First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.7.7, 17.8.5, 17.9.2.
First published (updated )
Severity
6.4
AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.6.4, 17.7.3, 17.8.1 or above.
First published (updated )
Severity
6.4
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection.

1 / 2
Source: NVD
First published (updated )
Severity
5.4
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. An attacker could inject HMTL into the child item search potentially leading to XSS in certain situations.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.7.6, 17.8.4, 17.9.1 or above.
First published (updated )
Severity
5.4
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to read Security policy YAML

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.7.6, 17.8.4, 17.9.1 or above.
First published (updated )
Severity
5.3
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCable potentially allowed revoked Personal Access Tokens access to streaming results.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.6.5, 17.7.4, 17.8.2 or above.
First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions on critical project data.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.7.4, 17.8.2 or above
First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.

First published (updated )
Severity
4.2
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

1 / 2
Source: MITRE

Remedy

Upgrade to version 17.8.2, 17.7.4 or 17.6.5.
First published (updated )
Severity
2.7
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2 which allowed a user with a custom permission to approve pending membership requests beyond the maximum number of allowed users.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.7.7, 17.8.5, 17.9.2 or above.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203