GitLab Inc.
First CVE: Jun 9, 2020Active for: 6 years
1,266
CVEs Published
More CVEs Published than 92% of tracked CNAs
180.9
Avg CVEs / Year
More Avg CVEs / Year than 93% of tracked CNAs
6.0
Avg CVSS Score
Higher Avg CVSS Score than 9% of tracked CNAs
0.4%
In CISA KEV
Higher KEV Rate than 84% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by GitLab Inc. as a CNA, 82.6% affect products that GitLab Inc. develops as a vendor.
82.6%
17.4%
Self-reported: 1,046Third-party: 220
Of all the CVEs published that affect products developed by GitLab Inc., 73.6% are self-published by GitLab Inc. as a CNA.
73.6%
26.4%
Self-published: 1,046Published by other CNAs: 376
Trends Over Time
The number and severity of CVEs published by GitLab Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2020
6 years ago
Most Recent CVE
Jul 8, 2026
16 days ago
Top CVEs
All CVEs published by GitLab Inc. as a CNA, regardless of affected vendor or product.
1,266 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-7028CRITICAL An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5. | Jan 12, 2024 | 9.8 | 99 | YES | YES |
CVE-2021-22205CRITICAL An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resul | Apr 23, 2021 | 10.0 | 99 | YES | YES |
CVE-2021-22204HIGH Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image | Apr 23, 2021 | 7.8 | 98 | YES | YES |
CVE-2021-22175CRITICAL When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to expl | Jun 11, 2021 | 9.8 | 93 | YES | YES |
CVE-2022-1162CRITICAL A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14 | Apr 4, 2022 | 9.8 | 86 | NO | YES |
CVE-2022-2992CRITICAL A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via | Oct 17, 2022 | 9.9 | 85 | NO | YES |
CVE-2023-2825HIGH An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the | May 26, 2023 | 7.5 | 83 | NO | YES |
CVE-2022-2185HIGH A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated use | Jul 1, 2022 | 8.8 | 81 | NO | YES |
CVE-2021-39935HIGH An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 | Dec 13, 2021 | 7.5 | 81 | YES | NO |
CVE-2022-2884CRITICAL A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code ex | Oct 17, 2022 | 9.9 | 80 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA1,266 CVEs
67%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local103 (8.1%)
Network1,161 (91.7%)
Unknown0 (0.0%)
Physical1 (0.1%)
Adjacent Network1 (0.1%)
Attack Complexity
Low1,215 (96.0%)
High51 (4.0%)
Unknown0 (0.0%)
User Interaction
None906 (71.6%)
Unknown0 (0.0%)
Required360 (28.4%)
Privileges Required
Low633 (50.0%)
High101 (8.0%)
None532 (42.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (1266 CVEs).
CISA KEV
5 CVEs
0.4% of CVEs· 84th percentile
Metasploit
7 CVEs
0.6% of CVEs· 83rd percentile
Nuclei
10 CVEs
0.8% of CVEs· 79th percentile
ExploitDB
6 CVEs
0.5% of CVEs· 77th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by GitLab Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by GitLab Inc. as a CNA — matched by CVE ID, not by organization name.