Gitlab
This hub aggregates every CVE we track for Gitlab, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
1,428
CVEs tracked
59
Critical
295
High
4
In CISA KEV
Severity distribution
MEDIUM895HIGH295LOW179CRITICAL59
Monthly trend
21
10
12
12
10
19
22
8
14
20
10
15
16
10
14
11
13
25
27
22
31
23
20
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Gitlab.
- CVE-2025-14562Incorrect Authorization in GitLab3.1
- CVE-2026-3093Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab4.7
- CVE-2026-4672Missing Authorization in GitLab4.3
- CVE-2026-6267Insertion of Sensitive Information Into Sent Data in GitLab8.5
- CVE-2026-6336Incorrect Authorization in GitLab5.3
- CVE-2026-12436Improperly Controlled Modification of Dynamically-Determined Object Attributes in GitLab8.4
- CVE-2026-13113Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab6.5
- CVE-2026-14341Missing Authorization in GitLab4.9
- CVE-2026-14351Exposure of Sensitive Information Through Metadata in GitLab4.3
- CVE-2026-15077Improper Neutralization of Input Used for LLM Prompting in GitLab4.3
- CVE-2026-15831Generation of Incorrect Security Tokens in GitLab4.3
- CVE-2026-15975Allocation of Resources Without Limits or Throttling in GitLab7.5
- CVE-2026-16553Insufficiently Protected Credentials in GitLab5.4
- CVE-2025-12506Use of Incorrectly-Resolved Name or Reference in GitLab3.5
- CVE-2026-6352Incorrect Authorization in GitLab2.7
Product normalization is registry-driven with AI assist and human review. How it works