Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.3 CVE-2026-5952

Incorrect Authorization in GitLab_CVE-2026-5952

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that un...

GitLab GitLab 17.11 CVE
MEDIUM 4.3 CVE-2026-5796

Incorrect Authorization in GitLab_CVE-2026-5796

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that und...

GitLab GitLab 13.6 CVE
MEDIUM 5.4 CVE-2026-5309

Authorization Bypass Through User-Controlled Key in GitLab_CVE-2026-5309

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under ...

GitLab GitLab 18.6 CVE
LOW 3.1 CVE-2026-3176

Missing Authorization in GitLab_CVE-2026-3176

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under ...

GitLab GitLab 18.6 CVE
MEDIUM 5.3 CVE-2026-2238

Missing Authorization in GitLab_CVE-2026-2238

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that und...

GitLab GitLab 17.5 CVE
MEDIUM 4.3 CVE-2026-1606

Improper Control of Generation of Code (‘Code Injection’) in GitLab_CVE-2026-1606

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that und...

GitLab GitLab 14.8 CVE
HIGH 8.7 CVE-2026-13311

shell-quote parse() is quadratic in token count, enabling denial of service_CVE-2026-13311

shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies th...

ljharb shell-quote CVE
HIGH 8.6 CVE-2026-12053

Insertion of Sensitive Information into Log File in GitLab_CVE-2026-12053

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user ...

GitLab GitLab 19.1 CVE
MEDIUM 5.3 CVE-2026-11379

Incorrect Authorization in GitLab_CVE-2026-11379

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in w...

GitLab GitLab 13.11 CVE
HIGH 8 CVE-2026-10712

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) in GitLab_CVE-2026-10712

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that un...

GitLab GitLab 18.10 CVE