Technology · GitLab
GitLab Enterprise Edition vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 117 vulnerabilities in GitLab Enterprise Edition: 1 in the last 7 days and 45 in the last 90 days, 6 of them critical and 3 exploited in the wild. The most recent, CVE-2026-89078, was published on 24 September 2026.
- Last 7 days
- 1
- Last 90 days
- 45
- Critical, all time
- 6
- Exploited in the wild
- 3
About GitLab Enterprise Edition
A self-managed software development platform that includes additional features for enterprise-level security, compliance, and planning.
Latest GitLab Enterprise Edition vulnerabilities
- CVE-2026-89078: GitLab double free in regular expression parsercriticalCVSS 9.9EPSS 0.4%
- CVE-2026-86341: GitLab EE access control bypass in protected environment approval rulesmediumCVSS 4.4EPSS 0.3%
- CVE-2026-8030: GitLab improper input validation in namespace transfermediumCVSS 4.3EPSS 0.4%
- CVE-2026-7514: GitLab Generic Package Registry authorization bypassmediumCVSS 4.3EPSS 0.3%
- CVE-2026-79708: GitLab EE scheduled pipeline execution policy test privilege escalationhighCVSS 8.5EPSS 0.3%
- CVE-2026-78252: GitLab Cross-site Scripting in Markdown JSON table rendererhighCVSS 8.2EPSS 0.4%
- CVE-2026-3855: GitLab CE/EE improper input validation in Terraform state APIlowCVSS 3.1EPSS 0.3%
- CVE-2026-1168: GitLab denial of service in GraphQL complexity limiterhighCVSS 7.5EPSS 0.5%
- CVE-2026-19619: GitLab Content Editor cross-site scripting in HTML sanitizationmediumCVSS 4.7EPSS 0.2%
- CVE-2026-16794: GitLab EE authorization bypass in compliance framework managementmediumCVSS 4.3EPSS 0.3%
- CVE-2025-14871: GitLab denial of service in GraphQL complexity limiterhighCVSS 7.5EPSS 0.5%
- CVE-2026-88765: GitLab EE buffer overflow in Advanced Search indexinghighCVSS 8.5EPSS 0.7%
- CVE-2026-13210: GitLab CE/EE improper CI/CD variable scope validationhighCVSS 7.7EPSS 0.2%
- CVE-2026-12910: GitLab SAML SSO authentication bypassmediumCVSS 5.4EPSS 0.2%
- CVE-2026-87719: GitLab EE GraphQL deserialization in Duo ChatcriticalCVSS 9.9EPSS 0.6%
- CVE-2026-85706: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1…criticalexploited in the wildCVSS 10EPSS 91.4%
- CVE-2026-7487: GitLab EE improper authorization in merge request approval ruleslowCVSS 3.5EPSS 0.3%
- CVE-2026-77801: GitLab denial of service in import pipelinemediumCVSS 6.5EPSS 0.4%
- CVE-2026-3035: GitLab EE improper access control in protected environmentsmediumCVSS 5.5EPSS 0.3%
- CVE-2026-18252: GitLab EE arbitrary command execution in Claude AI agenthighCVSS 7.3EPSS 0.4%
- CVE-2026-15387: GitLab EE improper handling of untrusted data in Pipeline Execution PoliciesmediumCVSS 4.3EPSS 0.2%
- CVE-2025-10903: GitLab Enterprise Edition denial of service in SCIM APImediumCVSS 6.5EPSS 0.4%
- CVE-2026-10053: GitLab path traversal in package registryhighCVSS 8.5EPSS 0.8%
- CVE-2026-19650: GitLab CSRF in GraphQL multiplex query handlerhighCVSS 7.1EPSS 0.6%
- CVE-2026-19478: GitLab CE/EE code injection via GraphQL directivecriticalCVSS 9.4EPSS 60.2%
Most severe GitLab Enterprise Edition vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-85706: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1…criticalexploited in the wildCVSS 10EPSS 91.4%
- CVE-2023-7028: GitLab Community and Enterprise Editions Improper Access Control Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2021-39935: GitLab CE/EE SSRF in CI Lint APIcriticalexploited in the wildCVSS 7.5EPSS 58.4%
- CVE-2026-87719: GitLab EE GraphQL deserialization in Duo ChatcriticalCVSS 9.9EPSS 0.6%
- CVE-2026-89078: GitLab double free in regular expression parsercriticalCVSS 9.9EPSS 0.4%
- CVE-2026-19478: GitLab CE/EE code injection via GraphQL directivecriticalCVSS 9.4EPSS 60.2%
- CVE-2025-9222: GitLab CE/EE stored XSS in GitLab Flavored Markdown placeholdershighCVSS 8.7EPSS 0.4%
- CVE-2026-7377: GitLab EE stored XSS in customizable analytics dashboardshighCVSS 8.7EPSS 0.0%
- CVE-2026-6073: GitLab Enterprise Edition cross-site scripting due to improper sanitizationhighCVSS 8.7EPSS 0.0%
- CVE-2026-6896: GitLab Enterprise Edition XSS in vulnerability evidence table rendererhighCVSS 8.7
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 8 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 12 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 3 | 1 | |
| 24 Aug 2026 | 6 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 2 | 2 | |
| 14 Sep 2026 | 13 | 0 | |
| 21 Sep 2026 | 1 | 1 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/gitlab-ee.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "GitLab Enterprise Edition vulnerabilities", https://junglewise.ai/threats/technologies/gitlab-ee, 26 September 2026.