<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – GitLab (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/gitlab.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/gitlab-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – GitLab (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:40 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-4868 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4868</guid>
    <pubDate>Wed, 27 May 2026 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4868</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authenticated user to cause specific Duo AI workflows to run under another user's identity due to improper user identity resolution when triggering Duo AI workflow runners.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44895 – GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44895</guid>
    <pubDate>Tue, 26 May 2026 22:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44895</strong></p>
  <p>GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-Control-Allow-Origin: * on every response. The structural defect is that the SSE server stands up a stateful, mutation-capable RPC endpoint that is backed by the operator's GITLAB_PERSONAL_ACCESS_TOKEN without any inboun…</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3515 – A vulnerability in the `GitHubRepository` block of the `prefect-github` integrat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3515</guid>
    <pubDate>Sun, 24 May 2026 05:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3515</strong></p>
  <p>A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line options via the `reference` field. The `reference` field is concatenated directly into a `git clone` command string without proper sanitization, and then parsed by `shlex.split()`. This enables injection of options such as `-c`, lead…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7481 – GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7481</guid>
    <pubDate>Thu, 14 May 2026 06:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7481</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to execute arbitrary JavaScript in other users' browsers due to improper input sanitization.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7377 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7377</guid>
    <pubDate>Thu, 14 May 2026 06:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7377</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6073 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6073</guid>
    <pubDate>Thu, 14 May 2026 06:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6073</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to execute arbitrary JavaScript in other users' browsers due to improper input sanitization.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1659 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1659</guid>
    <pubDate>Thu, 14 May 2026 06:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1659</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted requests due to insufficient input validation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14870 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14870</guid>
    <pubDate>Thu, 14 May 2026 06:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14870</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted JSON payloads due to insufficient input validation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14869 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14869</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14869</guid>
    <pubDate>Thu, 14 May 2026 06:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14869</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted payloads on certain API endpoints.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14869">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5816 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5816</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5816</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-41</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5262 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5262</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5262</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5262</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5262">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4922 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4922</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4922</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40161 – Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40161</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40161</guid>
    <pubDate>Tue, 21 Apr 2026 17:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40161</strong></p>
  <p>Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled serverURL when the user omits the token parameter. A tenant with TaskRun or PipelineRun create permission can e…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40161">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5173 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5173</guid>
    <pubDate>Wed, 08 Apr 2026 23:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5173</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-749</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1092 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1092</guid>
    <pubDate>Wed, 08 Apr 2026 23:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1092</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service due to improper input validation of JSON payloads.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12664 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12664</guid>
    <pubDate>Wed, 08 Apr 2026 23:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12664</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2370 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2370</guid>
    <pubDate>Mon, 30 Mar 2026 00:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2370</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with minimal workspace permissions to obtain installation credentials and impersonate the GitLab app due to improper authorization checks.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-233</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3988 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3988</guid>
    <pubDate>Wed, 25 Mar 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3988</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to cause a denial of service by making the GitLab instance unresponsive due to improper input validation in GraphQL request processing.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3857 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3857</guid>
    <pubDate>Wed, 25 Mar 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3857</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to execute arbitrary GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2995 – GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2995</guid>
    <pubDate>Wed, 25 Mar 2026 17:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2995</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to add email addresses to targeted user accounts due to improper sanitization of HTML content.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1090 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1090</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1090</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inject JavaScript in a browser due to improper sanitization of placeholder content in markdown processing.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1069 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1069</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1069</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by sending specially crafted GraphQL requests due to uncontrolled recursion under certain circumstances.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14513 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14513</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14513</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially crafted JSON payloads in the protected branches API.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13929 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13929</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13929</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by issuing specially crafted requests to repository archive endpoints under certain conditions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1662 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1662</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1662</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause Denial of Service by sending specially crafted requests to the Jira events endpoint.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1388 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1388</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1388</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause regular expression denial of service by sending specially crafted input to a merge request endpoint under certain conditions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0752 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0752</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0752</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that under certain circumstances, could have allowed an unauthenticated user to inject arbitrary scripts into the Mermaid sandbox UI.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14511 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14511</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14511</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted files to the container registry event endpoint under certain conditions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0958 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0958</guid>
    <pubDate>Wed, 11 Feb 2026 12:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0958</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through memory or CPU exhaustion by bypassing JSON validation middleware limits.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-436</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0595 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0595</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0595</guid>
    <pubDate>Wed, 11 Feb 2026 12:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0595</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to add unauthorized email addresses to victim accounts through HTML injection in test case titles.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0595">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8099 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8099</guid>
    <pubDate>Wed, 11 Feb 2026 12:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8099</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7659 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7659</guid>
    <pubDate>Wed, 11 Feb 2026 12:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7659</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to steal tokens and access private repositories by abusing incomplete validation in the Web IDE.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14560 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14560</guid>
    <pubDate>Wed, 11 Feb 2026 12:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14560</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by injecting malicious content into vulnerability code flow.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-1868 – GitLab has remediated a vulnerability in the Duo Workflow Service component of G...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1868</guid>
    <pubDate>Mon, 09 Feb 2026 07:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-1868</strong></p>
  <p>GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in which AI Gateway was vulnerable to insecure template expansion of user supplied data via crafted Duo Agent Platform Flow definitions. This vulnerability could be used to cause Denial of Service or gai…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0723 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0723</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0723</guid>
    <pubDate>Thu, 22 Jan 2026 15:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0723</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an individual with existing knowledge of a victim's credential ID to bypass two-factor authentication by submitting forged device responses.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0723">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13928 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13928</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13928</guid>
    <pubDate>Thu, 22 Jan 2026 15:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13928</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to cause a denial of service condition by exploiting incorrect authorization validation in API endpoints.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13928">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13927 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13927</guid>
    <pubDate>Thu, 22 Jan 2026 15:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13927</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted requests with malformed authentication data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11224 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11224</guid>
    <pubDate>Wed, 14 Jan 2026 19:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11224</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to execute stored cross-site scripting through improper input validation in the Kubernetes proxy functionality.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0830 – Processing specially crafted workspace folder names could allow for arbitrary co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0830</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0830</guid>
    <pubDate>Fri, 09 Jan 2026 21:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0830</strong></p>
  <p>Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces.  To mitigate, users should update to the latest version.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0830">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9222 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9222</guid>
    <pubDate>Fri, 09 Jan 2026 10:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9222</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13772 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13772</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13772</guid>
    <pubDate>Fri, 09 Jan 2026 10:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13772</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces by manipulating namespace identifiers in API requests.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13772">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13761 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13761</guid>
    <pubDate>Fri, 09 Jan 2026 10:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13761</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an  authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61916 – Spinnaker is an open source, multi-cloud continuous delivery platform. Versions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61916</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61916</guid>
    <pubDate>Mon, 05 Jan 2026 22:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61916</strong></p>
  <p>Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primary impact is allowing users to fetch data from a remote URL. This data can be then injected into spinnaker pipelines via helm or other methods to extract things LIKE idmsv1 authentication data. This also includes calling…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61916">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12029 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12029</guid>
    <pubDate>Thu, 11 Dec 2025 08:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12029</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI."</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8405 – GitLab has remediated a security issue in GitLab CE/EE affecting all versions fr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8405</guid>
    <pubDate>Thu, 11 Dec 2025 05:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8405</strong></p>
  <p>GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12716 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12716</guid>
    <pubDate>Thu, 11 Dec 2025 04:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12716</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by creating wiki pages with malicious content.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12562 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12562</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12562</guid>
    <pubDate>Thu, 11 Dec 2025 04:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12562</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted GraphQL queries that bypass query complexity limits.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12562">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9183 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9183</guid>
    <pubDate>Fri, 05 Dec 2025 17:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9183</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context under specific conditions.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12571 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12571</guid>
    <pubDate>Wed, 26 Nov 2025 20:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12571</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an unauthenticated user to cause a Denial of Service condition by sending specifically crafted requests containing malicious JSON payloads.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11702 – GitLab has remediated an issue in EE affecting all versions from 17.1 before 18...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11702</guid>
    <pubDate>Wed, 29 Oct 2025 07:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11702</strong></p>
  <p>GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker with specific permissions to hijack project runners from other projects.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11447 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11447</guid>
    <pubDate>Mon, 27 Oct 2025 00:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11447</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending GraphQL requests with crafted JSON payloads.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10497 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10497</guid>
    <pubDate>Mon, 27 Oct 2025 00:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10497</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11340 – GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11340</guid>
    <pubDate>Thu, 09 Oct 2025 12:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11340</strong></p>
  <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records by exploiting incorrectly scoped GraphQL mutations.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10004 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10004</guid>
    <pubDate>Thu, 09 Oct 2025 12:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10004</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4460 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4460</guid>
    <pubDate>Wed, 01 Oct 2025 12:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4460</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdkfd: Fix UBSAN shift-out-of-bounds warning  If get_num_sdma_queues or get_num_xgmi_sdma_queues is 0, we end up doing a shift operation where the number of bits shifted equals number of bits in the operand. This behaviour is undefined.  Set num_sdma_queues or num_xgmi_sdma_queues to ULLONG_MAX, if the count is >= number of…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8014 – Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8014</guid>
    <pubDate>Sat, 27 Sep 2025 17:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8014</strong></p>
  <p>Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9958 – An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9958</guid>
    <pubDate>Fri, 26 Sep 2025 09:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9958</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9642 – An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9642</guid>
    <pubDate>Fri, 26 Sep 2025 09:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9642</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10858 – An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10858</guid>
    <pubDate>Fri, 26 Sep 2025 09:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10858</strong></p>
  <p>An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that allows unauthenticated users to cause a Denial of Service (DoS) condition while uploading specifically crafted large JSON files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6454 – An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6454</guid>
    <pubDate>Fri, 12 Sep 2025 06:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6454</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to make unintended internal requests through proxy environments by injecting crafted sequences.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2256 – An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2256</guid>
    <pubDate>Fri, 12 Sep 2025 06:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2256</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate users by sending multiple concurrent large SAML responses.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7739 – An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7739</guid>
    <pubDate>Wed, 13 Aug 2025 18:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7739</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7734 – An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7734</guid>
    <pubDate>Wed, 13 Aug 2025 18:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7734</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6186 – An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6186</guid>
    <pubDate>Wed, 13 Aug 2025 18:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6186</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8279 – Insufficient input validation within GitLab Language Server 7.6.0 and later befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8279</guid>
    <pubDate>Mon, 28 Jul 2025 14:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8279</strong></p>
  <p>Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4700 – An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4700</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4700</guid>
    <pubDate>Wed, 23 Jul 2025 18:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4700</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to XSS.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4700">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4439 – An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4439</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4439</guid>
    <pubDate>Wed, 23 Jul 2025 18:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4439</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4439">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6948 – An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6948</guid>
    <pubDate>Thu, 10 Jul 2025 09:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6948</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4994 – An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4994</guid>
    <pubDate>Fri, 20 Jun 2025 19:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4994</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutations.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5121 – An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5121</guid>
    <pubDate>Fri, 20 Jun 2025 18:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5121</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2443 – An issue has been discovered in GitLab EE that allows for cross-site-scripting a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2443</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2443</guid>
    <pubDate>Fri, 20 Jun 2025 18:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2443</strong></p>
  <p>An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2443">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-50084 – In the Linux kernel, the following vulnerability has been resolved:

dm raid: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50084</guid>
    <pubDate>Wed, 18 Jun 2025 11:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-50084</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  dm raid: fix address sanitizer warning in raid_status  There is this warning when using a kernel with the address sanitizer and running this testsuite: https://gitlab.com/cki-project/kernel-tests/-/tree/main/storage/swraid/scsi_raid  ================================================================== BUG: KASAN: slab-out-of-bound…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0673 – An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0673</guid>
    <pubDate>Thu, 12 Jun 2025 11:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0673</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an attacker to trigger an infinite redirect loop, potentially leading to a denial of service condition.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4278 – An issue has been discovered in GitLab CE/EE affecting all versions starting wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4278</guid>
    <pubDate>Thu, 12 Jun 2025 10:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4278</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2254 – An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2254</guid>
    <pubDate>Thu, 12 Jun 2025 10:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2254</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1763 – An issue has been discovered in GitLab EE that allows for cross-site-scripting a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1763</guid>
    <pubDate>Fri, 30 May 2025 11:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1763</strong></p>
  <p>An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0993 – An issue has been discovered in GitLab CE/EE affecting all versions before 17.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0993</guid>
    <pubDate>Thu, 22 May 2025 15:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0993</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1908 – An issue has been discovered in GitLab EE/CE that could allow an attacker to tra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1908</guid>
    <pubDate>Thu, 24 Apr 2025 08:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1908</strong></p>
  <p>An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-840</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2255 – An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2255</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2255</guid>
    <pubDate>Thu, 27 Mar 2025 13:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2255</strong></p>
  <p>An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Certain error messages could allow Cross-Site Scripting attacks (XSS). for AppSec.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2255">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2242 – An improper access control vulnerability in GitLab CE/EE affecting all versions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2242</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2242</guid>
    <pubDate>Thu, 27 Mar 2025 13:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2242</strong></p>
  <p>An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2242">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0811 – An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0811</guid>
    <pubDate>Thu, 27 Mar 2025 13:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0811</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0555 – A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0555</guid>
    <pubDate>Mon, 03 Mar 2025 16:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0555</strong></p>
  <p>A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0475 – An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0475</guid>
    <pubDate>Mon, 03 Mar 2025 11:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0475</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-7102 – An issue was discovered in GitLab CE/EE affecting all versions starting from 16...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7102</guid>
    <pubDate>Thu, 13 Feb 2025 01:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-7102</strong></p>
  <p>An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0376 – An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0376</guid>
    <pubDate>Wed, 12 Feb 2025 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0376</strong></p>
  <p>An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions via a change page.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-10383 – An issue has been discovered in the gitlab-web-ide-vscode-fork component distrib...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10383</guid>
    <pubDate>Fri, 07 Feb 2025 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-10383</strong></p>
  <p>An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-2878 – An issue has been discovered in GitLab CE/EE affecting all versions starting fro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2878</guid>
    <pubDate>Wed, 05 Feb 2025 13:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-2878</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9631 – An issue was discovered in GitLab CE/EE affecting all versions starting from 13...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9631</guid>
    <pubDate>Wed, 05 Feb 2025 11:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9631</strong></p>
  <p>An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0314 – An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0314</guid>
    <pubDate>Fri, 24 Jan 2025 03:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0314</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site scripting.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8233 – An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8233</guid>
    <pubDate>Thu, 12 Dec 2024 12:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8233</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could cause a denial of service with requests for diff files on a commit or merge request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11274 – An issue was discovered in GitLab CE/EE affecting all versions starting from 16...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11274</guid>
    <pubDate>Thu, 12 Dec 2024 12:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11274</strong></p>
  <p>An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8114 – An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8114</guid>
    <pubDate>Tue, 26 Nov 2024 19:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8114</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9693 – An issue was discovered in GitLab CE/EE affecting all versions starting from 16...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9693</guid>
    <pubDate>Thu, 14 Nov 2024 11:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9693</strong></p>
  <p>An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific configurations.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8312 – An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8312</guid>
    <pubDate>Thu, 24 Oct 2024 10:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8312</strong></p>
  <p>An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-9164 – An issue was discovered in GitLab EE affecting all versions starting from 12.5 p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9164</guid>
    <pubDate>Fri, 11 Oct 2024 13:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-9164</strong></p>
  <p>An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8970 – An issue was discovered in GitLab CE/EE affecting all versions starting from 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8970</guid>
    <pubDate>Fri, 11 Oct 2024 13:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8970</strong></p>
  <p>An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-6530 – A cross-site scripting issue has been discovered in GitLab affecting all version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6530</guid>
    <pubDate>Thu, 10 Oct 2024 12:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-6530</strong></p>
  <p>A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2. When adding a authorizing an application, it can be made to render as HTML under specific circumstances.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8977 – An issue has been discovered in GitLab EE affecting all versions starting from 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8977</guid>
    <pubDate>Thu, 10 Oct 2024 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8977</strong></p>
  <p>An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46683 – In the Linux kernel, the following vulnerability has been resolved:

drm/xe: pre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46683</guid>
    <pubDate>Fri, 13 Sep 2024 06:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46683</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/xe: prevent UAF around preempt fence  The fence lock is part of the queue, therefore in the current design anything locking the fence should then also hold a ref to the queue to prevent the queue from being freed.  However, currently it looks like we signal the fence and then drop the queue ref, but if something is waiting o…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6678 – An issue was discovered in GitLab CE/EE affecting all versions starting from 8.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6678</guid>
    <pubDate>Thu, 12 Sep 2024 19:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6678</strong></p>
  <p>An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6678">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
