Gitlab
1,451 known vulnerabilities
Top Products
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions start
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions start
In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2
Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 1
Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 befor
Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0
It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions fro
An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting fr
An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting fro
An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting fr
An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9
An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting fr
Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 pri
Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting f
Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting f
An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting fr
Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 al
Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior
Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions start
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions start
A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 befor
A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE
Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8
A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8
Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and
A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 p
An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior t
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 pr
Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.
Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting f
Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal env
An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DO
A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 all
Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project
Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-m
In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and al
Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to
An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting fr
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions star
An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 befor
An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigg
Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows a
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions start
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting fr
An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab
Frequently Asked Questions
How many CVEs affect Gitlab?
Gitlab has 1,451 CVE records in our database, including 57 critical and 304 high severity vulnerabilities. 4 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Gitlab vulnerabilities?
Gitlab has 57 critical severity (CVSS 9.0+) and 304 high severity (CVSS 7.0-8.9) vulnerabilities. 4 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Gitlab vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Gitlab products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Gitlab Vulnerabilities
CyberStrike scans your infrastructure for Gitlab vulnerabilities and provides real-time remediation guidance.
Get Started