CVE-2026-2995
- EPSS 0.19%
- Veröffentlicht 25.03.2026 16:33:58
- Zuletzt bearbeitet 26.03.2026 17:42:57
GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to add email addresses to targeted user accounts due to improper sa...
CVE-2026-3857
- EPSS 0.17%
- Veröffentlicht 25.03.2026 16:33:53
- Zuletzt bearbeitet 30.03.2026 15:19:33
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to execute arbitrary GraphQL mutations on behalf of authentic...
CVE-2026-3988
- EPSS 0.48%
- Veröffentlicht 25.03.2026 16:33:43
- Zuletzt bearbeitet 26.03.2026 17:42:09
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to cause a denial of service by making the GitLab instance unr...
CVE-2026-4363
- EPSS 0.12%
- Veröffentlicht 25.03.2026 15:16:50
- Zuletzt bearbeitet 26.03.2026 11:56:57
GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user to gain unauthorized access to resources d...
CVE-2026-1182
- EPSS 0.19%
- Veröffentlicht 12.03.2026 01:33:23
- Zuletzt bearbeitet 13.03.2026 13:20:51
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to gain unauthorized access to confidential issue title created in...
CVE-2026-0602
- EPSS 0.24%
- Veröffentlicht 11.03.2026 16:16:22
- Zuletzt bearbeitet 17.03.2026 20:59:01
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose metadata from private issues, merge requests, epics, m...
CVE-2026-1069
- EPSS 0.4%
- Veröffentlicht 11.03.2026 16:16:22
- Zuletzt bearbeitet 13.03.2026 12:35:38
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by sending specially crafted GraphQL requests due to uncontrolled recursion und...
CVE-2026-1090
- EPSS 0.23%
- Veröffentlicht 11.03.2026 16:16:22
- Zuletzt bearbeitet 13.03.2026 12:36:26
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inj...
CVE-2026-1230
- EPSS 0.19%
- Veröffentlicht 11.03.2026 16:16:22
- Zuletzt bearbeitet 17.03.2026 20:55:04
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause repository downloads to contain different code than displa...
CVE-2026-1663
- EPSS 0.19%
- Veröffentlicht 11.03.2026 16:16:22
- Zuletzt bearbeitet 13.03.2026 13:24:07
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with group import permissions to create labels in private projects...