GitLab Inc.

First CVE: Jun 9, 2020Active for: 6 years
1,266
CVEs Published
More CVEs Published than 92% of tracked CNAs
180.9
Avg CVEs / Year
More Avg CVEs / Year than 93% of tracked CNAs
6.0
Avg CVSS Score
Higher Avg CVSS Score than 9% of tracked CNAs
0.4%
In CISA KEV
Higher KEV Rate than 84% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by GitLab Inc. as a CNA, 82.6% affect products that GitLab Inc. develops as a vendor.

82.6%
17.4%
Self-reported: 1,046Third-party: 220

Of all the CVEs published that affect products developed by GitLab Inc., 73.6% are self-published by GitLab Inc. as a CNA.

73.6%
26.4%
Self-published: 1,046Published by other CNAs: 376

Trends Over Time

The number and severity of CVEs published by GitLab Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2020
6 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Top CVEs

All CVEs published by GitLab Inc. as a CNA, regardless of affected vendor or product.

1,266 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.
Jan 12, 20249.899YESYES
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resul
Apr 23, 202110.099YESYES
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
Apr 23, 20217.898YESYES
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to expl
Jun 11, 20219.893YESYES
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14
Apr 4, 20229.886NOYES
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via
Oct 17, 20229.985NOYES
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the
May 26, 20237.583NOYES
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated use
Jul 1, 20228.881NOYES
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5
Dec 13, 20217.581YESNO
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code ex
Oct 17, 20229.980NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA1,266 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local103 (8.1%)
Network1,161 (91.7%)
Unknown0 (0.0%)
Physical1 (0.1%)
Adjacent Network1 (0.1%)
Attack Complexity
Low1,215 (96.0%)
High51 (4.0%)
Unknown0 (0.0%)
User Interaction
None906 (71.6%)
Unknown0 (0.0%)
Required360 (28.4%)
Privileges Required
Low633 (50.0%)
High101 (8.0%)
None532 (42.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (1266 CVEs).

CISA KEV
5 CVEs
0.4% of CVEs· 84th percentile
Metasploit
7 CVEs
0.6% of CVEs· 83rd percentile
Nuclei
10 CVEs
0.8% of CVEs· 79th percentile
ExploitDB
6 CVEs
0.5% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by GitLab Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by GitLab Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs