gitlab

1,383 tracked vulnerabilities.

CVE-2025-9957 LOW
Incorrect Authorization in GitLab
Apr 22, 2026
CVSS 2.7
EPSS 0.00
CVE-2025-6016 MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
Apr 22, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-3922 MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
Apr 22, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-0186 MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
Apr 22, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-9484 MEDIUM
Missing Authorization in GitLab
Apr 08, 2026
CVSS 4.3
EPSS 0.00
CVE-2025-12664 HIGH
Improper Validation of Specified Quantity in Input in GitLab
Apr 08, 2026
CVSS 7.5
EPSS 0.00
CVE-2025-14595 MEDIUM
Missing Authorization in GitLab
Mar 25, 2026
CVSS 4.3
EPSS 0.00
CVE-2025-13436 MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
Mar 25, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-13078 MEDIUM
Improper Validation of Specified Quantity in Input in GitLab
Mar 25, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-12555 MEDIUM
GitLab CE/EE 15.1-18.7.5/18.8-18.8.5/18.9-18.9.1 - Info Disclosure
Mar 11, 2026
CVSS 4.3
EPSS 0.00
CVE-2025-14513 HIGH
GitLab 16.11-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - DoS via Protected Branches API
Mar 11, 2026
CVSS 7.5
EPSS 0.00
CVE-2025-13929 HIGH
GitLab 10.0-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Unauthenticated Denial of Service via Repository Archive Endpoint
Mar 11, 2026
CVSS 7.5
EPSS 0.00
CVE-2025-13690 MEDIUM
GitLab 16.11-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Authenticated Denial of Service via Webhook Custom Header Input
Mar 11, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-12704 LOW
GitLab EE 18.2-18.9.2 - Auth Bypass
Mar 11, 2026
CVSS 3.5
EPSS 0.00
CVE-2025-12697 LOW
GitLab 15.5-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Authenticated Datadog API Credential Exposure
Mar 11, 2026
CVSS 2.2
EPSS 0.00
CVE-2025-12576 MEDIUM
GitLab 9.3-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Authenticated Denial of Service via Webhook Response Handling
Mar 11, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-14511 HIGH
GitLab 12.2-18.7.4, 18.8-18.8.4, 18.9-18.9.0 - Unauthenticated Denial of Service via Container Registry Event Endpoint
Feb 25, 2026
CVSS 7.5
EPSS 0.00
CVE-2025-3525 MEDIUM
GitLab 9.0-18.7.4, 18.8-18.8.4, 18.9-18.9.0 - Authenticated Denial of Service via CI Trigger API
Feb 25, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-14103 MEDIUM
GitLab CE/EE 17.7-18.9 - Privilege Escalation
Feb 25, 2026
CVSS 4.3
EPSS 0.00
CVE-2025-8099 HIGH
GitLab 10.8-18.6.5, 18.7-18.7.3, 18.8-18.8.3 - Unauthenticated Denial of Service via GraphQL Query Flooding
Feb 11, 2026
CVSS 7.5
EPSS 0.00
CVE-2025-7659 HIGH
GitLab CE/EE <18.6.6-18.8.4 - Info Disclosure
Feb 11, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-14594 LOW
GitLab CE/EE <18.6.6-18.8.4 - Info Disclosure
Feb 11, 2026
CVSS 3.5
EPSS 0.00
CVE-2025-14592 LOW
GitLab CE/EE <18.6.6-18.8.4 - Privilege Escalation
Feb 11, 2026
CVSS 3.7
EPSS 0.00
CVE-2025-14560 HIGH
GitLab CE/EE <18.6.6-18.8.4 - Privilege Escalation
Feb 11, 2026
CVSS 7.3
EPSS 0.00
CVE-2025-12575 MEDIUM
GitLab 18.0-18.6.5, 18.7-18.7.3, 18.8-18.8.3 - Authenticated Server-Side Request Forgery
Feb 11, 2026
CVSS 5.4
EPSS 0.00