gitlab
1,383 tracked vulnerabilities.
CVE-2025-12653
MEDIUM
GitLab CE/EE <18.4.5-18.6.1 - Info Disclosure
Nov 26, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-12571
HIGH
GitLab 17.10-18.4.5, 18.5-18.5.3, 18.6-18.6.1 - Unauthenticated Denial of Service via Malicious JSON Payloads
Nov 26, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-9825
MEDIUM
GitLab 13.7-18.2.8, 18.3-18.3.4, 18.4-18.4.2 - Authenticated Sensitive CI/CD Variable Exposure via GraphQL API
Nov 21, 2025
CVSS 5.0
EPSS 0.00
CVE-2025-12983
LOW
GitLab 16.9-18.3.5, 18.4-18.4.3, 18.5-18.5.1 - Authenticated Denial of Service via Nested Markdown Formatting
Nov 15, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-7736
LOW
GitLab CE/EE <18.3.6-18.5.2 - Auth Bypass
Nov 15, 2025
CVSS 3.1
EPSS 0.00
CVE-2025-7000
MEDIUM
GitLab CE/EE <18.3.6-18.5.2 - Info Disclosure
Nov 15, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-6945
LOW
GitLab 17.8-18.3.5, 18.4-18.4.3, 18.5-18.5.1 - Information Disclosure via Merge Request Comment Prompt Injection
Nov 15, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-6171
MEDIUM
GitLab 13.2-18.3.5, 18.4-18.4.3, 18.5-18.5.1 - Authenticated Missing Authorization via Packages API
Nov 15, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-2615
MEDIUM
GitLab <18.3.6-18.5.2 - Info Disclosure
Nov 15, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-11990
LOW
GitLab 18.4.0-18.4.3 & 18.5.0-18.5.1 CSRF Token Exposure via Input Validation Bypass
Nov 15, 2025
CVSS 3.1
EPSS 0.00
CVE-2025-11865
MEDIUM
GitLab 18.1-18.3.6, 18.4-18.4.4, 18.5-18.5.2 - Incorrect Authorization
Nov 15, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-11702
HIGH
GitLab 17.1.0-18.3.4, 18.4.0-18.4.2, 18.5.0 - Authenticated Project Runner Hijacking via Missing Authorization
Oct 29, 2025
CVSS 8.5
EPSS 0.00
CVE-2025-6601
LOW
GitLab EE <18.4.3-18.5.1 - Privilege Escalation
Oct 27, 2025
CVSS 2.7
EPSS 0.00
CVE-2025-11989
LOW
GitLab 17.6.0-18.3.4, 18.4-18.4.2, 18.5 - Authenticated Missing Authorization via Quick Action Command Injection
Oct 27, 2025
CVSS 3.7
EPSS 0.00
CVE-2025-11974
MEDIUM
GitLab 11.7-18.3.4, 18.4-18.4.2, 18.5 - Unauthenticated Denial of Service via Large File Upload
Oct 27, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-11971
MEDIUM
GitLab 10.6.0-18.3.4, 18.4.0-18.4.2, 18.5.0 - Authenticated Unauthorized Pipeline Execution via Commit Manipulation
Oct 27, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-11447
HIGH
GitLab 11.0-18.3.4, 18.4.0-18.4.2, 18.5.0 - Unauthenticated Denial of Service via Crafted GraphQL JSON Payloads
Oct 27, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-10497
HIGH
GitLab 17.10-18.3.4, 18.4-18.4.2, 18.5 - Unauthenticated Denial of Service via Crafted Payloads
Oct 27, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-2934
MEDIUM
GitLab 5.2-18.2.7, 18.3-18.3.3, 18.4-18.4.1 - Authenticated Denial of Service via Malicious Webhook Endpoint
Oct 09, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-11340
HIGH
GitLab EE <18.3.4-18.4.2 - Privilege Escalation
Oct 09, 2025
CVSS 7.7
EPSS 0.00
CVE-2025-10004
HIGH
GitLab 13.12-18.2.8, 18.3-18.3.4, 18.4-18.4.2 - Denial of Service via Crafted GraphQL Queries
Oct 09, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-8014
HIGH
GitLab 11.10-18.2.6, 18.3-18.3.2, 18.4-18.4.0 - Unauthenticated Denial of Service via GraphQL Query Complexity Bypass
Sep 27, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-5069
LOW
GitLab CE/EE <18.2.7-18.4.1 - Privilege Escalation
Sep 26, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-11042
MEDIUM
GitLab 17.2-18.2.6, 18.3-18.3.2, 18.4 - Denial of Service via GraphQL Query
Sep 26, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-10868
LOW
GitLab CE/EE <18.2.7-18.4.1 - Info Disclosure
Sep 26, 2025
CVSS 3.5
EPSS 0.00