Gitlab
1,451 known vulnerabilities
Top Products
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting fro
An issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4
An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4,
An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting fr
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions start
Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions start
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions start
Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions start
An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 befor
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions start
An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 befor
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions start
An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starti
An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4,
An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.
An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4,
Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to
Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5
Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15
An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, an
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions start
Bypass of healthcheck endpoint allow list affecting all versions from 12.0 prior to 15.2.5, 15.3 prior to 15.3.4, and 15
An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 1
An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4,
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.5
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting fr
An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all vers
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions start
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 10.8 before 15.1.6, all version
An issue has been discovered in GitLab EE affecting all versions starting from 13.7 before 15.2.5, all versions starting
An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting
It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE affecting all versions fr
Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions st
Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to
Serialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and
A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior
Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions before before 15.2.5, all versions s
An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4,
An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 befor
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting fr
Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an a
An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 befor
An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 b
Frequently Asked Questions
How many CVEs affect Gitlab?
Gitlab has 1,451 CVE records in our database, including 57 critical and 304 high severity vulnerabilities. 4 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Gitlab vulnerabilities?
Gitlab has 57 critical severity (CVSS 9.0+) and 304 high severity (CVSS 7.0-8.9) vulnerabilities. 4 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Gitlab vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Gitlab products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Gitlab Vulnerabilities
CyberStrike scans your infrastructure for Gitlab vulnerabilities and provides real-time remediation guidance.
Get Started