Gitlab

Gitlab

1222 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Published 27.09.2025 17:15:33
  • Last modified 03.10.2025 18:23:37

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resou...

  • EPSS 0.04%
  • Published 26.09.2025 10:15:47
  • Last modified 29.09.2025 13:11:50

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (Do...

  • EPSS 0.01%
  • Published 26.09.2025 10:15:47
  • Last modified 29.09.2025 13:12:20

An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to gain unauthorized access to confidential issues by creating a pr...

  • EPSS 0.01%
  • Published 26.09.2025 10:15:46
  • Last modified 29.09.2025 13:11:31

An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 where certain string conversion methods exhibit performance degradation with large inputs.

  • EPSS 0.04%
  • Published 26.09.2025 09:15:49
  • Last modified 29.09.2025 13:10:11

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover.

  • EPSS 0.01%
  • Published 26.09.2025 09:15:49
  • Last modified 29.09.2025 13:10:20

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.

  • EPSS 0.01%
  • Published 26.09.2025 09:15:48
  • Last modified 29.09.2025 13:10:00

A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 that could have allowed a developer with specific group management permissions to escalate ...

  • EPSS 0.03%
  • Published 26.09.2025 09:15:31
  • Last modified 29.09.2025 13:09:42

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to create a denial-of-service condition by exploiting an unprotected...

  • EPSS 0.01%
  • Published 26.09.2025 09:15:31
  • Last modified 29.09.2025 13:09:51

An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintainers can exploit a vulnerability where they can assign custom roles to users with permissions exceedi...

  • EPSS 0.04%
  • Published 26.09.2025 09:15:30
  • Last modified 29.09.2025 13:09:35

An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that allows unauthenticated users to cause a Denial of Service (DoS) condition while uploading specifically crafted large JSON fi...