gitlab

7 records · 0 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names gitlab as an affected vendor, highest CVSS first.

  1. CRITICAL 9.9CVE-2026-93577

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due …

    gitlab

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.9CVE-2026-89078

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due …

    gitlab

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.7CVE-2026-92470

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to access sensitive CI/CD variable values from debug-m…

    gitlab

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 5.4CVE-2026-92874

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with an MCP-scoped token to perform actions beyond …

    gitlab

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 4.3CVE-2026-92530

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to spoof merge request authorship and attribute con…

    gitlab

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 4.3CVE-2026-92529

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass admin-config…

    gitlab

    AI risk analysis on Exploit-DB.ai →

  7. LOW 3.1CVE-2026-92628

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race condition, the MCP search tool's shared state handling could have caused search results to be returned u…

    gitlab

    AI risk analysis on Exploit-DB.ai →