GitLab
1,477 CVEs tracked. 5 of them are in CISA KEV.
This hub aggregates every CVE we track for GitLab, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
GitLab CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 10 |
| 2024-11 | 12 |
| 2024-12 | 12 |
| 2025-01 | 10 |
| 2025-02 | 19 |
| 2025-03 | 22 |
| 2025-04 | 8 |
| 2025-05 | 14 |
| 2025-06 | 20 |
| 2025-07 | 10 |
| 2025-08 | 15 |
| 2025-09 | 16 |
| 2025-10 | 10 |
| 2025-11 | 14 |
| 2025-12 | 11 |
| 2026-01 | 13 |
| 2026-02 | 25 |
| 2026-03 | 27 |
| 2026-04 | 22 |
| 2026-05 | 31 |
| 2026-06 | 24 |
| 2026-07 | 20 |
| 2026-08 | 24 |
| 2026-09 | 24 |
Severity
How the 1,477 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical64
- High312
- Medium917
- Low183
Latest CVEs
The 15 most recently published vulnerabilities affecting GitLab.
- CVE-2026-89078Double Free in GitLab9.9
- CVE-2026-92530Use of Less Trusted Source in GitLab4.3
- CVE-2026-92470Missing Authorization in GitLab7.7
- CVE-2026-92529Incorrect Authorization in GitLab4.3
- CVE-2026-92874Incorrect Authorization in GitLab5.4
- CVE-2026-92628Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitLab3.1
- CVE-2026-93577Integer Overflow or Wraparound in GitLab9.9
- CVE-2026-86341Access Control Check Implemented After Asset is Accessed in GitLab4.4
- CVE-2024-11222Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab6.4
- CVE-2025-14871Allocation of Resources Without Limits or Throttling in GitLab7.5
- CVE-2026-1168Allocation of Resources Without Limits or Throttling in GitLab7.5
- CVE-2026-3855Improper Control of Resource Identifiers ('Resource Injection') in GitLab3.1
- CVE-2026-7514Missing Authorization in GitLab4.3
- CVE-2026-8030Missing Authorization in GitLab4.3
- CVE-2026-16794Missing Authorization in GitLab4.3
Product grouping is registry-driven, with AI assist and human review. How it works