GitLab vulnerabilities
23 CVEs tracked
GitLab has appeared in recent reporting primarily due to a critical publicly disclosed RCE Proof of Concept (PoC), alongside several patched vulnerabilities. The PoC targets unpatched self-managed 18.11.3 servers, allowing any authenticated user to execute commands as the 'git' user by exploiting a Jupyter notebook diff chain, without needing admin rights. Concurrently, addressed CVEs like CVE-2026-12436 (improper CI/CD configuration modification by authenticated users) highlight ongoing access control issues. Defenders must prioritize immediate patching to versions 19.0.5, 19.1.3, or 19.2.1 and review access controls, particularly for the published RCE chain and improper authorization flaws in CI/CD settings.
Azərbaycanca: GitLab, son hesabat dövründə kritik təhlükəsizlik problemləri ilə gündəmə gəlib. Xüsusilə, 18.11.3 versiyasında autentifikasiya olunmuş istifadəçiyə Jupyter notebook diff-i vasitəsilə 'git' istifadəçisi kimi əmrlər icra etməyə imkan verən RCE (Remote Code Execution) zəifliyi üçün açıq PoC (Proof of Concept) dərc edilib və bu, dərhal yeniləmə tələb edir. Paralel olaraq, CVE-2026-12436 ilə izlənən autentifikasiya olunmuş istifadəçinin başqa bir istifadəçinin CI/CD konfiqurasiyasını dəyişməsinə şərait yaradan boşluq da diqqət mərkəzindədir. Müdafiəçilər, xüsusilə 19.0.5, 19.1.3, 19.2.1 versiyalarından əvvəlki bütün qurğular üçün kritik yamaqları tətbiq etməli və səlahiyyət yoxlamalarındakı zəiflikləri izləməlidirlər.
This vendor's CVEs23
- CVE-2026-19650EPSS 0.47%
- CVE-2026-19478EPSS 6%
- CVE-2026-19228EPSS 0.23%
- CVE-2026-18433EPSS 0.24%
- CVE-2026-16627EPSS 0.36%
- CVE-2026-16553EPSS 0.25%
- CVE-2026-16494EPSS 0.33%
- CVE-2026-16049EPSS 0.22%
- CVE-2026-15975EPSS 0.47%
- CVE-2026-15831EPSS 0.22%
- CVE-2026-15423EPSS 0.26%
- CVE-2026-15217EPSS 0.26%
- CVE-2026-15216EPSS 0.27%
- CVE-2026-15077EPSS 0.25%
- CVE-2026-14351EPSS 0.29%
- CVE-2026-14341EPSS 0.42%
- CVE-2026-13113EPSS 0.20%
- CVE-2026-12436EPSS 0.31%
- CVE-2026-4879EPSS 0.24%
- CVE-2026-4672EPSS 0.29%
- CVE-2026-3093EPSS 0.24%
- CVE-2025-14562EPSS 0.22%
- CVE-2025-9486EPSS 0.22%
This hub is built from skopnix's own reporting on GitLab: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.