GitLab
1,392 CVEs tracked since 2014. Since Apr 2021, 5 of them reached CISA KEV.
GitLab CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-04 | 12 | 1 |
| 2021-05 | 5 | 0 |
| 2021-06 | 12 | 1 |
| 2021-07 | 11 | 0 |
| 2021-08 | 20 | 0 |
| 2021-09 | null or fewer | |
| 2021-10 | 36 | 0 |
| 2021-11 | 16 | 0 |
| 2021-12 | 22 | 1 |
| 2022-01 | 13 | 0 |
| 2022-02 | null or fewer | |
| 2022-03 | 14 | 0 |
| 2022-04 | 24 | 0 |
| 2022-05 | 14 | 0 |
| 2022-06 | 8 | 0 |
| 2022-07 | 18 | 0 |
| 2022-08 | 16 | 0 |
| 2022-09 | null or fewer | |
| 2022-10 | 30 | 0 |
| 2022-11 | 13 | 0 |
| 2022-12 | null or fewer | |
| 2023-01 | 24 | 0 |
| 2023-02 | 5 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 26 | 0 |
| 2023-05 | 15 | 0 |
| 2023-06 | 16 | 0 |
| 2023-07 | 12 | 0 |
| 2023-08 | 16 | 0 |
| 2023-09 | 26 | 0 |
| 2023-10 | null or fewer | |
| 2023-11 | 8 | 0 |
| 2023-12 | 17 | 0 |
| 2024-01 | 10 | 1 |
| 2024-02 | 12 | 0 |
| 2024-03 | 4 | 0 |
| 2024-04 | 9 | 0 |
| 2024-05 | 13 | 0 |
| 2024-06 | 16 | 0 |
| 2024-07 | 12 | 0 |
| 2024-08 | 15 | 0 |
| 2024-09 | 21 | 0 |
| 2024-10 | 10 | 0 |
| 2024-11 | 12 | 0 |
| 2024-12 | 12 | 0 |
| 2025-01 | 9 | 0 |
| 2025-02 | 19 | 0 |
| 2025-03 | 19 | 0 |
| 2025-04 | 8 | 0 |
| 2025-05 | 14 | 0 |
| 2025-06 | 20 | 0 |
| 2025-07 | 11 | 0 |
| 2025-08 | 15 | 0 |
| 2025-09 | 16 | 0 |
| 2025-10 | 10 | 0 |
| 2025-11 | 14 | 0 |
| 2025-12 | 11 | 0 |
| 2026-01 | 13 | 0 |
| 2026-02 | 26 | 0 |
| 2026-03 | 27 | 0 |
| 2026-04 | 22 | 0 |
| 2026-05 | 31 | 0 |
| 2026-06 | 25 | 0 |
| 2026-07 | 21 | 0 |
| 2026-08 | 25 | 0 |
| 2026-09 | 17 | 1 |
Products
The products that kept showing up in GitLab's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting GitLab.
- CVE-2026-89078Double Free in GitLab9.9
- CVE-2026-92530Use of Less Trusted Source in GitLab4.3
- CVE-2026-92470Missing Authorization in GitLab7.7
- CVE-2026-92529Incorrect Authorization in GitLab4.3
- CVE-2026-92874Incorrect Authorization in GitLab5.4
- CVE-2026-92628Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitLab3.1
- CVE-2026-93577Integer Overflow or Wraparound in GitLab9.9
- CVE-2026-86341Access Control Check Implemented After Asset is Accessed in GitLab4.4
- CVE-2024-11222Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab6.4
- CVE-2025-14871Allocation of Resources Without Limits or Throttling in GitLab7.5
- CVE-2026-1168Allocation of Resources Without Limits or Throttling in GitLab7.5
- CVE-2026-3855Improper Control of Resource Identifiers ('Resource Injection') in GitLab3.1
- CVE-2026-7514Missing Authorization in GitLab4.3
- CVE-2026-8030Missing Authorization in GitLab4.3
- CVE-2026-16794Missing Authorization in GitLab4.3
The record
- Peak rank
- #9 in Mar 2020
- Busiest month shown
- Oct 2021, 36 CVEs
- Months with a KEV entry
- 5 since Apr 2021
- Monthly snapshots
- 84 since 2014