Gitlab
1,451 known vulnerabilities
Top Products
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 where an infinite loop exist when
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a sto
Client side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user system
Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike
In all versions of GitLab, marshalled session keys were being stored in Redis.
An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to se
An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unautho
Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccess
An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.
An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticat
An authorization issue in GitLab CE/EE version 9.4 and up allowed a group maintainer to modify group CI/CD variables whi
Insufficient input sanitization in wikis in GitLab version 13.8 and up allows an attacker to exploit a stored cross-site
A vulnerability was discovered in GitLab versions before 12.2. GitLab was vulnerable to a SSRF attack through the Outbou
An issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack t
An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demote
Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the
An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS
An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab we
An issue has been discovered in GitLab affecting all versions starting with 13.7. GitLab was vulnerable to a stored XSS
An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaus
Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a vict
A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting
An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project
An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed metho
An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is wr
A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 t
Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This aff
Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms v
Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclo
Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics sta
A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=
An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed
A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to tr
A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allo
The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malici
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request cou
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS
Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to sa
An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a f
An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could
Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names
CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instan
Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This inf
A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access t
A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name che
When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79
Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to pu
An issue has been discovered in GitLab Runner affecting all versions starting from 13.4.0 before 13.4.2, all versions st
Frequently Asked Questions
How many CVEs affect Gitlab?
Gitlab has 1,451 CVE records in our database, including 57 critical and 304 high severity vulnerabilities. 4 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Gitlab vulnerabilities?
Gitlab has 57 critical severity (CVSS 9.0+) and 304 high severity (CVSS 7.0-8.9) vulnerabilities. 4 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Gitlab vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Gitlab products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Gitlab Vulnerabilities
CyberStrike scans your infrastructure for Gitlab vulnerabilities and provides real-time remediation guidance.
Get Started