LIVE · cybersecurity feed
Live wire
vendor

Gitlab

44 CVEs published in the last four months and 8 stories. Exploited flaws first.

Critical1
High32
Medium9
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-194789.4criticalgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.19d ago
CVE-2026-152178.7highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4,24d ago
CVE-2026-152168.7highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4,24d ago
CVE-2026-68968.7highgitlabGitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, a59d ago
CVE-2026-10908.7highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, 178d ago
CVE-2026-73778.7highgitlabGitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, a114d ago
CVE-2026-60738.7highgitlabGitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, a114d ago
CVE-2026-100868.7highgitlabGitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, a72d ago
CVE-2026-100878.7highgitlabGitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5,86d ago
CVE-2026-74818.7highgitlabGitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, a114d ago
CVE-2026-120538.6highgitlabGitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain cond72d ago
CVE-2026-154238.5highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4,24d ago
CVE-2026-62678.5highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.338d ago
CVE-2026-192288.5highgitlabGitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 24d ago
CVE-2026-100538.5highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4,13d ago
CVE-2026-124368.4highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3,38d ago
CVE-2026-758718.2highgitlabGitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway 9d ago
CVE-2026-48688.2highgitlabGitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, 101d ago
CVE-2026-107128highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.72d ago
CVE-2026-166277.7highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain c24d ago
CVE-2025-139297.5highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6,178d ago
CVE-2025-148707.5highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.114d ago
CVE-2025-148697.5highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.114d ago
CVE-2026-72507.5highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.1186d ago
CVE-2026-10697.5highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allow178d ago
CVE-2026-159757.5highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3,38d ago
CVE-2026-16597.5highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6,114d ago
CVE-2025-145137.5highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6178d ago
CVE-2026-133207.3highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.459d ago
CVE-2026-182527.3highgitlabGitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, an10d ago
CVE-2026-85897.3highgitlabGitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.586d ago
CVE-2026-164947.1highgitlabGitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 24d ago
CVE-2026-196507.1highgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.19d ago
CVE-2025-136906.5mediumgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6178d ago
CVE-2025-125766.5mediumgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, 178d ago
CVE-2026-38485mediumgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, 178d ago
CVE-2026-06024.3mediumgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, 178d ago
CVE-2026-11824.3mediumgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, 177d ago
CVE-2026-17324.3mediumgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, 178d ago
CVE-2025-125554.3mediumgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.7.6, 18.8 before 18.8.6,178d ago
CVE-2026-16634.3mediumgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, 178d ago
CVE-2026-12304.1mediumgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, a178d ago
CVE-2025-127043.5lowgitlabGitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, an178d ago
CVE-2025-126972.2lowgitlabGitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6,178d ago

Filter the full tracker by Gitlab

Our coverage of Gitlab

CVE-2026-19478high

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

This week's cybersecurity landscape features AI-powered attacks targeting industrial control systems, a critical vulnerability in GitLab being actively exploited, and the discovery of trojanized npm packages delivering a sophisticated Linux backdoor. Additionally, researchers revealed a method to exploit expired credit cards for contactless payments, and several other vulnerabilities across various software platforms were highlighted.

CVE-2026-19478critical

GitLab Critical GraphQL Flaw Actively Exploited

GitLab has released an emergency patch for a critical vulnerability in its GraphQL API that allows unauthenticated attackers to modify or delete public projects and user data. Researchers from WatchTowr discovered the flaw, tracked as CVE-2026-19478, which has a CVSS score of 9.4 and is reportedly under active exploitation. The vulnerability affects self-managed installations, and users are urged to upgrade to specific patched versions, as older branches will not receive direct fixes.

gitlab

GitLab 19.3 helps enterprises scale agentic development securely

GitLab's latest update, version 19.3, enhances security and control for enterprises scaling agentic software development. Key features include running GitLab Duo Agent Platform within dedicated single-tenant environments, allowing custom model integration, and keeping AI data within existing security boundaries. The release also introduces improved secrets management, bulk SAST false positive detection, and a Flow Creator Agent for simplified automation.

CVE-2026-19478critical

GitLab Code Injection Vulnerability Actively Exploited

A critical code injection vulnerability in GitLab, identified as CVE-2026-19478, is being actively exploited shortly after its public disclosure. The flaw enables unauthenticated attackers to alter or delete public projects and their data under specific circumstances.

CVE-2026-19478critical

Critical GitLab Flaw Exploited Shortly After Disclosure

CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data. The post Critical GitLab Flaw Exploited Shortly After Disclosure appeared first on SecurityWeek.

CVE-2026-19478critical

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.1

vulnerabilitycritical

GitLab Patches Critical Code Injection Vulnerability

The security defect allows unauthenticated attackers to modify or delete user data and public projects. The post GitLab Patches Critical Code Injection Vulnerability appeared first on SecurityWeek.

CVE-2026-19478critical

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on