CVE Tools

GitLab

1,392 CVEs tracked since 2014. Since Apr 2021, 5 of them reached CISA KEV.

GitLab CVEs per month

Apr 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
GitLab CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-04121
2021-0550
2021-06121
2021-07110
2021-08200
2021-09null or fewer
2021-10360
2021-11160
2021-12221
2022-01130
2022-02null or fewer
2022-03140
2022-04240
2022-05140
2022-0680
2022-07180
2022-08160
2022-09null or fewer
2022-10300
2022-11130
2022-12null or fewer
2023-01240
2023-0250
2023-03null or fewer
2023-04260
2023-05150
2023-06160
2023-07120
2023-08160
2023-09260
2023-10null or fewer
2023-1180
2023-12170
2024-01101
2024-02120
2024-0340
2024-0490
2024-05130
2024-06160
2024-07120
2024-08150
2024-09210
2024-10100
2024-11120
2024-12120
2025-0190
2025-02190
2025-03190
2025-0480
2025-05140
2025-06200
2025-07110
2025-08150
2025-09160
2025-10100
2025-11140
2025-12110
2026-01130
2026-02260
2026-03270
2026-04220
2026-05310
2026-06250
2026-07210
2026-08250
2026-09171

Products

The products that kept showing up in GitLab's monthly top three, with their CVEs summed over those months.

  1. GitLab96160 months
  2. GitLab AI Gateway32 months
  3. GitLab Runner33 months
  4. Dast API Scanner11 month
  5. GitLab Ee11 month
  6. GitLab Language Server11 month
  7. GitLab Pages11 month
  8. GitLab Vscode Fork11 month
  9. Gitlab-vscode-extension11 month
  10. Language Server11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting GitLab.

  1. CVE-2026-89078Double Free in GitLab9.9
  2. CVE-2026-92530Use of Less Trusted Source in GitLab4.3
  3. CVE-2026-92470Missing Authorization in GitLab7.7
  4. CVE-2026-92529Incorrect Authorization in GitLab4.3
  5. CVE-2026-92874Incorrect Authorization in GitLab5.4
  6. CVE-2026-92628Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitLab3.1
  7. CVE-2026-93577Integer Overflow or Wraparound in GitLab9.9
  8. CVE-2026-86341Access Control Check Implemented After Asset is Accessed in GitLab4.4
  9. CVE-2024-11222Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab6.4
  10. CVE-2025-14871Allocation of Resources Without Limits or Throttling in GitLab7.5
  11. CVE-2026-1168Allocation of Resources Without Limits or Throttling in GitLab7.5
  12. CVE-2026-3855Improper Control of Resource Identifiers ('Resource Injection') in GitLab3.1
  13. CVE-2026-7514Missing Authorization in GitLab4.3
  14. CVE-2026-8030Missing Authorization in GitLab4.3
  15. CVE-2026-16794Missing Authorization in GitLab4.3

The record

Peak rank
#9 in Mar 2020
Busiest month shown
Oct 2021, 36 CVEs
Months with a KEV entry
5 since Apr 2021
Monthly snapshots
84 since 2014
GitLab's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store