GitLab Inc. maintains a widely deployed DevOps and CI/CD platform whose vulnerability footprint, despite a focused product portfolio, ranks prominently in the vulnerability landscape due to the platform's ubiquity in software development pipelines and its exposure across multiple logical layers. The recurring vulnerability classes affecting GitLab concentrate on web-application input handling, authorization logic, and resource-management weaknesses—including cross-site scripting, improper access controls, and resource exhaustion—that are characteristic of large, feature-rich application platforms handling untrusted user input and managing access to sensitive development artifacts. GitLab's disclosures span the core platform, its command-execution shell component, its CI runners, and its security-scanning tooling, reflecting the breadth of the ecosystem that organizations depend on for code hosting, pipeline orchestration, and integrated security analysis. Defenders should maintain current visibility into GitLab's advisory cadence and treat this platform as a high-value target requiring prompt patching strategies across all integrated components; current severity, exploitation, and exposure data are shown alongside this summary.
The number and severity of CVEs published that impact products developed by GitLab Inc. over time
Of all the CVEs published by GitLab Inc. as a CNA, 82.6% affect products that GitLab Inc. develops as a vendor.
Of all the CVEs published that affect products developed by GitLab Inc., 73.6% are self-published by GitLab Inc. as a CNA.
Signals from CVEs in this vendor scope (1423 CVEs).
1,423 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-7028CRITICAL An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5. | Jan 12, 2024 | 9.8 | 99 | YES | YES |
CVE-2021-22205CRITICAL An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resul | Apr 23, 2021 | 10.0 | 99 | YES | YES |
CVE-2021-22175CRITICAL When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to expl | Jun 11, 2021 | 9.8 | 93 | YES | YES |
CVE-2022-1162CRITICAL A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14 | Apr 4, 2022 | 9.8 | 86 | NO | YES |
CVE-2022-2992CRITICAL A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via | Oct 17, 2022 | 9.9 | 85 | NO | YES |
CVE-2023-2825HIGH An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the | May 26, 2023 | 7.5 | 83 | NO | YES |
CVE-2022-2185HIGH A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated use | Jul 1, 2022 | 8.8 | 81 | NO | YES |
CVE-2021-39935HIGH An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 | Dec 13, 2021 | 7.5 | 81 | YES | NO |
CVE-2022-2884CRITICAL A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code ex | Oct 17, 2022 | 9.9 | 80 | NO | YES |
CVE-2022-1175MEDIUM Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allo | Apr 4, 2022 | 6.1 | 77 | NO | YES |
Signals from CVEs in this vendor scope (1423 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by GitLab Inc..
Media articles that mention a CVE ID that affects a product developed by GitLab Inc. — matched by CVE ID, not by vendor name.