Solution sectors / devtools-ci
Developer Tools & CI/CD
Developer tooling — IDEs, CI/CD pipelines, source control and artifact registries — has deep access to source code and build infrastructure, making it a high-value supply-chain target. This hub tracks CVEs across it.
Cumulative CVEs
7,970
across 250 monthly snapshots
Latest month
160 · proj
-43.9% MoM · +135.3% YoY
Peak month
285
Jul 26
KEV this month
0
13 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem85%
- Mixed11%
- SaaS4%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Developer Tools & CI/CD.
- CVE-2025-9486Incorrect Privilege Assignment in GitLab3.3
- CVE-2026-4879Missing Authorization in GitLab4.3
- CVE-2026-6821Missing Authorization in GitLab4.3
- CVE-2026-15217Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab8.7
- CVE-2026-15216Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab8.7
- CVE-2026-16494Missing Authorization in GitLab7.1
- CVE-2026-18433Incorrect Authorization in GitLab4.3
- CVE-2026-19228Authorization Bypass Through User-Controlled Key in GitLab8.5
- CVE-2026-18952Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics Plugin8.1
- CVE-2026-19311Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin8.1
- CVE-2026-7427Allocation of Resources Without Limits or Throttling in GitLab5.3
- CVE-2026-8667Incorrect Authorization in GitLab4.3
- CVE-2026-15423Incorrect Authorization in GitLab8.5
- CVE-2026-16627Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab7.7
- CVE-2026-18244Missing Authorization in GitLab4.3
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| jenkins | 23 | 1 | · |
| eclipse | 11 | 1 | · |
| sonatype | 11 | · | · |
| gitpython-developers | 6 | 1 | · |
| github | 2 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| ci-cd | 28 | 3 | · | 3 | — | jenkins (5) · rancher (4) · jenkins multijob plugin (2) |
| build-test-tools | 12 | · | · | 3 | — | nexus repository 3 (10) · node-red (1) · rvtools (1) |
| — | 12 | · | · | 2 | — | milo (6) · theia (4) · enterprise server (2) |
| source-control | 7 | 1 | · | 2 | — | gitpython (6) · gitea (1) |
| ide-editor | 2 | · | · | 2 | — | jupyterlab (1) · kiro ide (1) |
| artifact-registry | 1 | · | · | 1 | — | nexus repository (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification