Where
AND
-Infinity
0
Severity
9.6
XSS
AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

1 / 2
Source: NVD
First published (updated )
Severity
9.1
AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to steal tokens and access private repositories by abusing incomplete validation in the Web IDE.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.6.6, 18.7.4, 18.8.4 or above.
First published (updated )
Severity
8.7
EPSS
0.02%
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.

1 / 2
Source: MITRE
First published (updated )
Severity
7.5
EPSS
0.05%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending repeated malformed SSH authentication requests.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.6.4, 18.7.2, 18.8.2 or above.
First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to cause a denial of service condition by exploiting incorrect authorization validation in API endpoints.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.6.4, 18.7.2, 18.8.2 or above.
First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted requests with malformed authentication data.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.6.4, 18.7.2, 18.8.2 or above.
First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through memory or CPU exhaustion by bypassing JSON validation middleware limits.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.6.6, 18.7.4, 18.8.4 or above.
First published (updated )
Severity
7.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.7.4, 18.8.4 or above.
First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.6.6, 18.7.4, 18.8.4 or above.
First published (updated )
Severity
7.5
Malicious File Upload
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service by uploading malicious files.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.6.6, 18.7.4, 18.8.4 or above.
First published (updated )
Severity
7.4
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an individual with existing knowledge of a victim's credential ID to bypass two-factor authentication by submitting forged device responses.

1 / 2
Source: NVD

Remedy

Upgrade to versions 18.6.4, 18.7.2, 18.8.2 or above.
First published (updated )
Severity
7.3
XSS
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by injecting malicious content into vulnerability code flow.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.6.6, 18.7.4, 18.8.4 or above.
First published (updated )
Severity
7.3
XSS
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to add unauthorized email addresses to victim accounts through HTML injection in test case titles.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.6.6, 18.7.4, 18.8.4 or above.
First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to create a denial of service condition by providing crafted responses to external API calls.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.5.5, 18.6.3, 18.7.1 or above.
First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under certain circumstances could have allowed an authenticated user to create a denial of service condition by configuring malformed Wiki documents that bypass cycle detection.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.6.4, 18.7.2, 18.8.2 or above.
First published (updated )
Severity
5.4
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user with specific permissions to remove all project runners from unrelated projects by manipulating GraphQL runner associations.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.5.5, 18.6.3, 18.7.1 or above.
First published (updated )
Severity
5.4
AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to inject malicious content into project labels titles.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.6.6, 18.7.4, 18.8.4 or above.
First published (updated )
Severity
5.3
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized operations by submitting GraphQL mutations through the GLQL API endpoint.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.6.6, 18.7.4, 18.8.4 or above.
First published (updated )
Severity
4.3
SSRF
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an authenticated user to perform server-side request forgery against internal services by bypassing protections in the Git repository import functionality.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.6.6, 18.7.4, 18.8.4 or above.
First published (updated )
Severity
3.5
AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.5.5, 18.6.3, 18.7.1 or above.
First published (updated )
Severity
3.5
AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view certain pipeline values by querying the API.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.6.6, 18.7.4, 18.8.4 or above.
First published (updated )
EOL
Mar 19, 2026
Support Ends
Jan 15, 2026

End of life: 3/19/2026, End of support: 1/15/2026, Latest version: 18.7.7

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203