Where
AND
-Infinity
0
Severity
7.1
CSRF
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions.

First published (updated )
Severity
8.5
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.

First published (updated )
Severity
8.4
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes when processing pipeline schedule inputs.

First published (updated )
Severity
7.3
XSS
AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.

First published (updated )
Severity
8.7
EPSS
0.06%
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

1 / 2
Source: MITRE
First published (updated )
Severity
8
EPSS
0.05%
XSS, Input Validation
AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.9.6, 18.10.4, 18.11.1 or above.
First published (updated )
Severity
7

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with minimal workspace permissions to obtain installation credentials and impersonate the GitLab app due to improper authorization checks.

First published (updated )
Severity
8.8
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval process resulted in unintended permission grants.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.11.5, 18.0.3, 18.1.1 or above.
First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to XSS.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.0.5, 18.1.3, 18.2.1 or above.
First published (updated )
Severity
7.7
XSS
AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.0.5, 18.1.3, 18.2.1 or above.
First published (updated )
Severity
7

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

First published (updated )
Severity
7.7
EPSS
0.01%
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.

1 / 2
Source: NVD

Remedy

Upgrade to version 18.2.7, 18.3.3 or 18.4.1 or above.
First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.

1 / 2
Source: MITRE

Remedy

Upgrade to version 18.2.8, 18.3.4 or 18.4.2
First published (updated )
Severity
7.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while using specific GraphQL queries.

1 / 2
Source: NVD

Remedy

Upgrade to versions 18.2.7, 18.3.3, 18.4.1 or above.
First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.1.6, 18.2.6, 18.3.2 or above.
First published (updated )
Severity
8.8
SSRF
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to make unintended internal requests through proxy environments by injecting crafted sequences.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.1.6, 18.2.6, 18.3.2 or above.
First published (updated )
Severity
8.7
EPSS
0.06%
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.

1 / 2
Source: NVD

Remedy

Upgrade to version 18.2.2 or above.
First published (updated )
Severity
8.7
EPSS
0.06%
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

1 / 2
Source: NVD

Remedy

Upgrade to versions 18.0.6, 18.1.4, 18.2.2 or above.
First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.

1 / 2
Source: NVD

Remedy

Upgrade to versions 18.1.4, 18.2.2 or above.
First published (updated )
Severity
7.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted payloads to specific integration API endpoints.

1 / 2
Source: NVD

Remedy

Upgrade to versions 18.0.6, 18.1.4, 18.2.2 or above.
First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.8.6, 17.9.3, 17.10.1 or above.
First published (updated )
Severity
8.8
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.8.6, 17.9.3, 17.10.1 or above.
First published (updated )
Severity
8.1
CSRF
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutations.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 16.11.5, 17.0.3, 17.1.1 or above.
First published (updated )
Severity
7.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.1.1, 17.0.3, 16.11.5 or above.
First published (updated )
Severity
7.5
EPSS
0.01%
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.10.7, 17.11.3, 18.0.1 or above.
First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.9.8, 17.10.6, 17.11.2 or above.
First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.10.8, 17.11.4, 18.0.2 or above.
First published (updated )
Severity
7.5
Input Validation
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper input validation in Tokens Names could be used to trigger a denial of service.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 17.10.8, 17.11.4, 18.0.2 or above.
First published (updated )
Severity
7.5
AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.

1 / 2
Source: MITRE

Remedy

Upgrade to versions 18.0.1, 17.11.3, 17.10.7 or above.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203