Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

GitLab Inc.

First CVE: Jan 24, 2014Active for: 12 yearsTotal CVEs: 1,423
53.2
VTI Score
TOP TARGET

GitLab Inc. maintains a widely deployed DevOps and CI/CD platform whose vulnerability footprint, despite a focused product portfolio, ranks prominently in the vulnerability landscape due to the platform's ubiquity in software development pipelines and its exposure across multiple logical layers. The recurring vulnerability classes affecting GitLab concentrate on web-application input handling, authorization logic, and resource-management weaknesses—including cross-site scripting, improper access controls, and resource exhaustion—that are characteristic of large, feature-rich application platforms handling untrusted user input and managing access to sensitive development artifacts. GitLab's disclosures span the core platform, its command-execution shell component, its CI runners, and its security-scanning tooling, reflecting the breadth of the ecosystem that organizations depend on for code hosting, pipeline orchestration, and integrated security analysis. Defenders should maintain current visibility into GitLab's advisory cadence and treat this platform as a high-value target requiring prompt patching strategies across all integrated components; current severity, exploitation, and exposure data are shown alongside this summary.

FAUCET AI Generated
1,423
Total CVEs
More Total CVEs than 100% of tracked vendors
10.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by GitLab Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 24, 2014
12 years ago
Most Recent CVE
Jul 8, 2026
17 days ago

Self-Reporting Analysis

Of all the CVEs published by GitLab Inc. as a CNA, 82.6% affect products that GitLab Inc. develops as a vendor.

82.6%
17.4%
Self-reported: 1,046 (82.6%)
Third-party: 220 (17.4%)

Of all the CVEs published that affect products developed by GitLab Inc., 73.6% are self-published by GitLab Inc. as a CNA.

73.6%
26.4%
Self-published: 1,046 (73.6%)
Other CNAs: 376 (26.4%)

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (1423 CVEs).

1,423 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-7028CRITICAL
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.
Jan 12, 20249.899YESYES
CVE-2021-22205CRITICAL
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resul
Apr 23, 202110.099YESYES
CVE-2021-22175CRITICAL
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to expl
Jun 11, 20219.893YESYES
CVE-2022-1162CRITICAL
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14
Apr 4, 20229.886NOYES
CVE-2022-2992CRITICAL
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via
Oct 17, 20229.985NOYES
CVE-2023-2825HIGH
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the
May 26, 20237.583NOYES
CVE-2022-2185HIGH
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated use
Jul 1, 20228.881NOYES
CVE-2021-39935HIGH
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5
Dec 13, 20217.581YESNO
CVE-2022-2884CRITICAL
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code ex
Oct 17, 20229.980NOYES
CVE-2022-1175MEDIUM
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allo
Apr 4, 20226.177NOYES
View all 1,423 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,423 CVEs
67%
24%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local22 (1.5%)
Network1,392 (97.8%)
Unknown7 (0.5%)
Physical1 (0.1%)
Adjacent Network1 (0.1%)
Attack Complexity
Low1,354 (95.2%)
High62 (4.4%)
Unknown7 (0.5%)
User Interaction
None1,124 (79.0%)
Unknown7 (0.5%)
Required292 (20.5%)
Privileges Required
Low764 (53.7%)
High105 (7.4%)
None547 (38.4%)
Unknown7 (0.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (1423 CVEs).

CISA KEV
4 CVEs
0.3% of CVEs· 99th percentile
Metasploit
8 CVEs
0.6% of CVEs· 97th percentile
Nuclei
12 CVEs
0.8% of CVEs· 95th percentile
ExploitDB
10 CVEs
0.7% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by GitLab Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by GitLab Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For GitLab Inc.'s Products

View all 5 CNAs →

Top CWEs