Gitlab
This hub aggregates every CVE we track for Gitlab, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
1,477
CVEs tracked
64
Critical
312
High
5
In CISA KEV
Severity distribution
MEDIUM917HIGH312LOW183CRITICAL64
Monthly trend
10
12
12
10
19
22
8
14
20
10
15
16
10
14
11
13
25
27
22
31
24
20
24
24
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Gitlab.
- CVE-2026-89078Double Free in GitLab9.9
- CVE-2026-92530Use of Less Trusted Source in GitLab4.3
- CVE-2026-92470Missing Authorization in GitLab7.7
- CVE-2026-92529Incorrect Authorization in GitLab4.3
- CVE-2026-92874Incorrect Authorization in GitLab5.4
- CVE-2026-92628Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitLab3.1
- CVE-2026-93577Integer Overflow or Wraparound in GitLab9.9
- CVE-2026-86341Access Control Check Implemented After Asset is Accessed in GitLab4.4
- CVE-2024-11222Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab6.4
- CVE-2025-14871Allocation of Resources Without Limits or Throttling in GitLab7.5
- CVE-2026-1168Allocation of Resources Without Limits or Throttling in GitLab7.5
- CVE-2026-3855Improper Control of Resource Identifiers ('Resource Injection') in GitLab3.1
- CVE-2026-7514Missing Authorization in GitLab4.3
- CVE-2026-8030Missing Authorization in GitLab4.3
- CVE-2026-16794Missing Authorization in GitLab4.3
Product normalization is registry-driven with AI assist and human review. How it works