Technology · GitLab
GitLab Community Edition vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 72 vulnerabilities in GitLab Community Edition: 2 in the last 7 days and 28 in the last 90 days, 6 of them critical and 3 exploited in the wild. The most recent, CVE-2026-93577, was published on 24 September 2026.
- Last 7 days
- 2
- Last 90 days
- 28
- Critical, all time
- 6
- Exploited in the wild
- 3
About GitLab Community Edition
An open-source end-to-end software development platform with built-in version control, issue tracking, and CI/CD.
Latest GitLab Community Edition vulnerabilities
- CVE-2026-93577: GitLab integer overflow in regular expression compilercriticalCVSS 9.9EPSS 0.4%
- CVE-2026-89078: GitLab double free in regular expression parsercriticalCVSS 9.9EPSS 0.4%
- CVE-2026-8030: GitLab improper input validation in namespace transfermediumCVSS 4.3EPSS 0.4%
- CVE-2026-7514: GitLab Generic Package Registry authorization bypassmediumCVSS 4.3EPSS 0.3%
- CVE-2026-78252: GitLab Cross-site Scripting in Markdown JSON table rendererhighCVSS 8.2EPSS 0.4%
- CVE-2026-3855: GitLab CE/EE improper input validation in Terraform state APIlowCVSS 3.1EPSS 0.3%
- CVE-2026-1168: GitLab denial of service in GraphQL complexity limiterhighCVSS 7.5EPSS 0.5%
- CVE-2026-19619: GitLab Content Editor cross-site scripting in HTML sanitizationmediumCVSS 4.7EPSS 0.2%
- CVE-2025-14871: GitLab denial of service in GraphQL complexity limiterhighCVSS 7.5EPSS 0.5%
- CVE-2026-13210: GitLab CE/EE improper CI/CD variable scope validationhighCVSS 7.7EPSS 0.2%
- CVE-2026-12910: GitLab SAML SSO authentication bypassmediumCVSS 5.4EPSS 0.2%
- CVE-2026-85706: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1…criticalexploited in the wildCVSS 10EPSS 91.4%
- CVE-2026-77801: GitLab denial of service in import pipelinemediumCVSS 6.5EPSS 0.4%
- CVE-2026-79788: Dradis Community Edition auth bypass in AI provider configurationhighCVSS 7.1EPSS 0.4%
- CVE-2026-10053: GitLab path traversal in package registryhighCVSS 8.5EPSS 0.8%
- CVE-2026-19650: GitLab CSRF in GraphQL multiplex query handlerhighCVSS 7.1EPSS 0.6%
- CVE-2026-19478: GitLab CE/EE code injection via GraphQL directivecriticalCVSS 9.4EPSS 60.2%
- CVE-2026-6267: GitLab CE/EE sensitive information exposure in WorkhorsehighCVSS 8.5
- CVE-2026-4672: GitLab CE/EE improper access control in Pipeline Test Report APImediumCVSS 4.3
- CVE-2026-3093: GitLab CE/EE cross-site scripting in paginated viewsmediumCVSS 4.7
- CVE-2026-15975: GitLab CE/EE denial of service in merge request discussionshighCVSS 7.5
- CVE-2026-14351: GitLab confidential issue title exposure in merge requestsmediumCVSS 4.3
- CVE-2026-14341: GitLab CE/EE improper authorization in protected branch configurationmediumCVSS 4.9
- CVE-2026-12436: GitLab CE/EE mass assignment in Pipeline Schedule APIhighCVSS 8.4
- CVE-2025-14562: GitLab incorrect authorization in merge request collaboration settingslowCVSS 3.1
Most severe GitLab Community Edition vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-85706: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1…criticalexploited in the wildCVSS 10EPSS 91.4%
- CVE-2023-7028: GitLab Community and Enterprise Editions Improper Access Control Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2021-39935: GitLab CE/EE SSRF in CI Lint APIcriticalexploited in the wildCVSS 7.5EPSS 58.4%
- CVE-2026-93577: GitLab integer overflow in regular expression compilercriticalCVSS 9.9EPSS 0.4%
- CVE-2026-89078: GitLab double free in regular expression parsercriticalCVSS 9.9EPSS 0.4%
- CVE-2026-19478: GitLab CE/EE code injection via GraphQL directivecriticalCVSS 9.4EPSS 60.2%
- CVE-2025-9222: GitLab CE/EE stored XSS in GitLab Flavored Markdown placeholdershighCVSS 8.7EPSS 0.4%
- CVE-2026-10053: GitLab path traversal in package registryhighCVSS 8.5EPSS 0.8%
- CVE-2026-5173: GitLab CE/EE unauthorized method invocation via WebSocketshighCVSS 8.5EPSS 0.4%
- CVE-2026-6267: GitLab CE/EE sensitive information exposure in WorkhorsehighCVSS 8.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 3 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 8 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 3 | 1 | |
| 24 Aug 2026 | 2 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 1 | 1 | |
| 14 Sep 2026 | 9 | 0 | |
| 21 Sep 2026 | 2 | 2 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/gitlab-ce.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "GitLab Community Edition vulnerabilities", https://junglewise.ai/threats/technologies/gitlab-ce, 26 September 2026.