gitlab

1,383 tracked vulnerabilities.

CVE-2025-12653 MEDIUM
GitLab CE/EE <18.4.5-18.6.1 - Info Disclosure
Nov 26, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-12571 HIGH
GitLab 17.10-18.4.5, 18.5-18.5.3, 18.6-18.6.1 - Unauthenticated Denial of Service via Malicious JSON Payloads
Nov 26, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-9825 MEDIUM
GitLab 13.7-18.2.8, 18.3-18.3.4, 18.4-18.4.2 - Authenticated Sensitive CI/CD Variable Exposure via GraphQL API
Nov 21, 2025
CVSS 5.0
EPSS 0.00
CVE-2025-12983 LOW
GitLab 16.9-18.3.5, 18.4-18.4.3, 18.5-18.5.1 - Authenticated Denial of Service via Nested Markdown Formatting
Nov 15, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-7736 LOW
GitLab CE/EE <18.3.6-18.5.2 - Auth Bypass
Nov 15, 2025
CVSS 3.1
EPSS 0.00
CVE-2025-7000 MEDIUM
GitLab CE/EE <18.3.6-18.5.2 - Info Disclosure
Nov 15, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-6945 LOW
GitLab 17.8-18.3.5, 18.4-18.4.3, 18.5-18.5.1 - Information Disclosure via Merge Request Comment Prompt Injection
Nov 15, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-6171 MEDIUM
GitLab 13.2-18.3.5, 18.4-18.4.3, 18.5-18.5.1 - Authenticated Missing Authorization via Packages API
Nov 15, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-2615 MEDIUM
GitLab <18.3.6-18.5.2 - Info Disclosure
Nov 15, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-11990 LOW
GitLab 18.4.0-18.4.3 & 18.5.0-18.5.1 CSRF Token Exposure via Input Validation Bypass
Nov 15, 2025
CVSS 3.1
EPSS 0.00
CVE-2025-11865 MEDIUM
GitLab 18.1-18.3.6, 18.4-18.4.4, 18.5-18.5.2 - Incorrect Authorization
Nov 15, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-11702 HIGH
GitLab 17.1.0-18.3.4, 18.4.0-18.4.2, 18.5.0 - Authenticated Project Runner Hijacking via Missing Authorization
Oct 29, 2025
CVSS 8.5
EPSS 0.00
CVE-2025-6601 LOW
GitLab EE <18.4.3-18.5.1 - Privilege Escalation
Oct 27, 2025
CVSS 2.7
EPSS 0.00
CVE-2025-11989 LOW
GitLab 17.6.0-18.3.4, 18.4-18.4.2, 18.5 - Authenticated Missing Authorization via Quick Action Command Injection
Oct 27, 2025
CVSS 3.7
EPSS 0.00
CVE-2025-11974 MEDIUM
GitLab 11.7-18.3.4, 18.4-18.4.2, 18.5 - Unauthenticated Denial of Service via Large File Upload
Oct 27, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-11971 MEDIUM
GitLab 10.6.0-18.3.4, 18.4.0-18.4.2, 18.5.0 - Authenticated Unauthorized Pipeline Execution via Commit Manipulation
Oct 27, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-11447 HIGH
GitLab 11.0-18.3.4, 18.4.0-18.4.2, 18.5.0 - Unauthenticated Denial of Service via Crafted GraphQL JSON Payloads
Oct 27, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-10497 HIGH
GitLab 17.10-18.3.4, 18.4-18.4.2, 18.5 - Unauthenticated Denial of Service via Crafted Payloads
Oct 27, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-2934 MEDIUM
GitLab 5.2-18.2.7, 18.3-18.3.3, 18.4-18.4.1 - Authenticated Denial of Service via Malicious Webhook Endpoint
Oct 09, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-11340 HIGH
GitLab EE <18.3.4-18.4.2 - Privilege Escalation
Oct 09, 2025
CVSS 7.7
EPSS 0.00
CVE-2025-10004 HIGH
GitLab 13.12-18.2.8, 18.3-18.3.4, 18.4-18.4.2 - Denial of Service via Crafted GraphQL Queries
Oct 09, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-8014 HIGH
GitLab 11.10-18.2.6, 18.3-18.3.2, 18.4-18.4.0 - Unauthenticated Denial of Service via GraphQL Query Complexity Bypass
Sep 27, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-5069 LOW
GitLab CE/EE <18.2.7-18.4.1 - Privilege Escalation
Sep 26, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-11042 MEDIUM
GitLab 17.2-18.2.6, 18.3-18.3.2, 18.4 - Denial of Service via GraphQL Query
Sep 26, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-10868 LOW
GitLab CE/EE <18.2.7-18.4.1 - Info Disclosure
Sep 26, 2025
CVSS 3.5
EPSS 0.00