| CVE-2026-8716 |
|
Medium |
May 27, 2026 |
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under
more...
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended.
less...
|
v18.5.6, v18.6.7, v18.7.7, v18.8.10, v18.9.8, v19.0.0, v18.9.7, v18.10.6, v18.11.3, v18.10.5
|
| CVE-2026-6713 |
|
Medium |
May 27, 2026 |
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under
more...
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an unauthorized user to enumerate private projects due to incorrect authorization checks.
less...
|
v18.5.6, v18.6.7, v18.7.7, v18.8.10, v18.9.8, v19.0.0, v18.9.7, v18.10.6, v18.11.3, v18.10.5
|
| CVE-2026-2601 |
|
Medium |
May 27, 2026 |
GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under ce
more...
GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to access sensitive deployment data on projects due to improper authorization checks.
less...
|
v18.5.6, v18.6.7, v18.7.7, v18.8.10, v18.9.8, v19.0.0, v18.9.7, v18.10.6, v18.11.3, v18.10.5
|
| CVE-2026-1402 |
|
Medium |
May 27, 2026 |
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under
more...
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to cause denial of service due to insufficient validation.
less...
|
v18.5.6, v18.6.7, v18.7.7, v18.8.10, v18.9.8, v19.0.0, v18.9.7, v18.10.6, v18.11.3, v18.10.5
|
| BDSA-2026-8004 |
|
Medium |
Apr 23, 2026 |
GitLab is vulnerable to resource exhaustion due to insufficient resource allocation limits in the `notes` endpoint. This could allow a remote attacker
more...
GitLab is vulnerable to resource exhaustion due to insufficient resource allocation limits in the `notes` endpoint. This could allow a remote attacker to trigger a denial-of-service (DoS).
less...
|
|
| BDSA-2026-8003 |
|
Medium |
Apr 23, 2026 |
GitLab is vulnerable to resource exhaustion due to insufficient resource allocation limits in the GraphQL API. This could allow a remote attacker to tr
more...
GitLab is vulnerable to resource exhaustion due to insufficient resource allocation limits in the GraphQL API. This could allow a remote attacker to trigger a denial-of-service (DoS) by sending a maliciously crafted query.
less...
|
|
| BDSA-2026-8002 |
|
Medium |
Apr 23, 2026 |
GitLab is vulnerable to resource exhaustion due to insufficient resource allocation limits in the `discussions` endpoint. This could allow a remote att
more...
GitLab is vulnerable to resource exhaustion due to insufficient resource allocation limits in the `discussions` endpoint. This could allow a remote attacker to trigger a denial-of-service (DoS) by sending maliciously crafted requests.
less...
|
|
| BDSA-2026-8001 |
|
Low |
Apr 23, 2026 |
GitLab is vulnerable to improper access control due to insufficient authorization checks in the project fork relationship API. This could allow an auth
more...
GitLab is vulnerable to improper access control due to insufficient authorization checks in the project fork relationship API. This could allow an authenticated user with project owner permissions to bypass group fork prevention settings.
less...
|
|
| BDSA-2026-8000 |
|
Medium |
Apr 23, 2026 |
GitLab is vulnerable to denial-of-service (DoS) due insufficient size limitation in the issue import component. This could allow an authenticated attac
more...
GitLab is vulnerable to denial-of-service (DoS) due insufficient size limitation in the issue import component. This could allow an authenticated attacker to exhaust server resources by supplying a crafted request, potentially disrupting service availability.
less...
|
|
| BDSA-2026-7997 |
|
Low |
Apr 23, 2026 |
GitLab is vulnerable to improper restrictions of UI elements due to incorrect URL handling in the Mermaid sandbox functionality. This could allow a rem
more...
GitLab is vulnerable to improper restrictions of UI elements due to incorrect URL handling in the Mermaid sandbox functionality. This could allow a remote attacker to render unauthorized content into another user's browser.
less...
|
|