Vendor
GitLab vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 129 vulnerabilities in GitLab: 6 in the last 7 days and 53 in the last 90 days, 9 of them critical and 5 exploited in the wild. The most recent, CVE-2026-93577, was published on 24 September 2026. 3 technologies have a page of their own.
- Last 7 days
- 6
- Last 90 days
- 53
- Critical, all time
- 9
- Exploited in the wild
- 5
About GitLab
DevOps platform providing git repository management, CI/CD pipelines, and related development tools.
GitLab technologies
Latest GitLab vulnerabilities
- CVE-2026-93577: GitLab integer overflow in regular expression compilercriticalCVSS 9.9EPSS 0.4%
- CVE-2026-92874: GitLab CE/EE incorrect authorization in MCP API scope enforcementmediumCVSS 5.4EPSS 0.1%
- CVE-2026-92530: GitLab merge request authorship spoofing in Direct Transfer importsmediumCVSS 4.3EPSS 0.1%
- CVE-2026-92529: GitLab EE authorization bypass in Duo Workflow governance controlsmediumCVSS 4.3EPSS 0.2%
- CVE-2026-92470: GitLab EE missing authorization in Duo AI job troubleshootinghighCVSS 7.7EPSS 0.2%
- CVE-2026-89078: GitLab double free in regular expression parsercriticalCVSS 9.9EPSS 0.4%
- CVE-2026-86341: GitLab EE access control bypass in protected environment approval rulesmediumCVSS 4.4EPSS 0.3%
- CVE-2026-8030: GitLab improper input validation in namespace transfermediumCVSS 4.3EPSS 0.4%
- CVE-2026-7514: GitLab Generic Package Registry authorization bypassmediumCVSS 4.3EPSS 0.3%
- CVE-2026-79708: GitLab EE scheduled pipeline execution policy test privilege escalationhighCVSS 8.5EPSS 0.3%
- CVE-2026-78252: GitLab Cross-site Scripting in Markdown JSON table rendererhighCVSS 8.2EPSS 0.4%
- CVE-2026-3855: GitLab CE/EE improper input validation in Terraform state APIlowCVSS 3.1EPSS 0.3%
- CVE-2026-1168: GitLab denial of service in GraphQL complexity limiterhighCVSS 7.5EPSS 0.5%
- CVE-2026-19619: GitLab Content Editor cross-site scripting in HTML sanitizationmediumCVSS 4.7EPSS 0.2%
- CVE-2026-16794: GitLab EE authorization bypass in compliance framework managementmediumCVSS 4.3EPSS 0.3%
- CVE-2025-14871: GitLab denial of service in GraphQL complexity limiterhighCVSS 7.5EPSS 0.5%
- CVE-2024-11222: GitLab race condition in merge request pipeline creationmediumCVSS 6.4EPSS 0.2%
- CVE-2026-88765: GitLab EE buffer overflow in Advanced Search indexinghighCVSS 8.5EPSS 0.7%
- CVE-2026-82837: GitLab CE/EE improper authorization in data emission endpointsmediumCVSS 5.3EPSS 0.5%
- CVE-2026-13210: GitLab CE/EE improper CI/CD variable scope validationhighCVSS 7.7EPSS 0.2%
- CVE-2026-12910: GitLab SAML SSO authentication bypassmediumCVSS 5.4EPSS 0.2%
- CVE-2026-87719: GitLab EE GraphQL deserialization in Duo ChatcriticalCVSS 9.9EPSS 0.6%
- CVE-2026-85706: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1…criticalexploited in the wildCVSS 10EPSS 91.4%
- CVE-2026-7487: GitLab EE improper authorization in merge request approval ruleslowCVSS 3.5EPSS 0.3%
- CVE-2026-77801: GitLab denial of service in import pipelinemediumCVSS 6.5EPSS 0.4%
Most severe GitLab vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-85706: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1…criticalexploited in the wildCVSS 10EPSS 91.4%
- CVE-2021-22205: GitLab Community and Enterprise Editions Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2021-22175: GitLab SSRF in internal network webhookscriticalexploited in the wildCVSS 9.8EPSS 69.7%
- CVE-2023-7028: GitLab Community and Enterprise Editions Improper Access Control Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2021-39935: GitLab CE/EE SSRF in CI Lint APIcriticalexploited in the wildCVSS 7.5EPSS 58.4%
- CVE-2026-87719: GitLab EE GraphQL deserialization in Duo ChatcriticalCVSS 9.9EPSS 0.6%
- CVE-2026-93577: GitLab integer overflow in regular expression compilercriticalCVSS 9.9EPSS 0.4%
- CVE-2026-89078: GitLab double free in regular expression parsercriticalCVSS 9.9EPSS 0.4%
- CVE-2026-19478: GitLab CE/EE code injection via GraphQL directivecriticalCVSS 9.4EPSS 60.2%
- CVE-2016-4340: GitLab privilege escalation in impersonate featurehighCVSS 8.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 8 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 13 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 3 | 1 | |
| 24 Aug 2026 | 6 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 2 | 2 | |
| 14 Sep 2026 | 15 | 0 | |
| 21 Sep 2026 | 6 | 2 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/gitlab.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "GitLab vulnerabilities", https://junglewise.ai/threats/vendors/gitlab, 26 September 2026.