21 entries matching gitlab — updated 2026-09-19 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-79708 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 | HIGH | 8.5 | 28%ile | NVD | 2026-09-16 |
| CVE-2026-78252 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 1 | HIGH | 8.2 | 33%ile | NVD | 2026-09-16 |
| CVE-2025-14871 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and | HIGH | 7.5 | 49%ile | NVD | 2026-09-16 |
| CVE-2026-1168 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and | HIGH | 7.5 | 49%ile | NVD | 2026-09-16 |
| CVE-2024-11222 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 1 | MEDIUM | 6.4 | 21%ile | NVD | 2026-09-16 |
| CVE-2026-92133 | Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API to | MEDIUM | 5.4 | 13%ile | NVD | 2026-09-16 |
| CVE-2026-19619 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 1 | MEDIUM | 4.7 | 23%ile | NVD | 2026-09-16 |
| CVE-2026-86341 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 | MEDIUM | 4.4 | 25%ile | NVD | 2026-09-16 |
| CVE-2026-16794 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19. | MEDIUM | 4.3 | 26%ile | NVD | 2026-09-16 |
| CVE-2026-7514 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 1 | MEDIUM | 4.3 | 26%ile | NVD | 2026-09-16 |
| CVE-2026-8030 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 1 | MEDIUM | 4.3 | 35%ile | NVD | 2026-09-16 |
| CVE-2026-3855 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and | LOW | 3.1 | 25%ile | NVD | 2026-09-16 |
| CVE-2026-61560 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (` | CRITICAL | 9.8 | 52%ile | NVD | 2026-09-15 |
| CVE-2026-61559 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1 | CRITICAL | 9.6 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-61568 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTT | CRITICAL | 9.6 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-88765 | GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 bef | HIGH | 8.5 | 52%ile | NVD | 2026-09-15 |
| GHSA-5648-rgj9-v224 | @zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticate | HIGH | 8.1 | — | GitHub | 2026-09-15 |
| CVE-2026-13210 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 1 | HIGH | 7.7 | 29%ile | NVD | 2026-09-15 |
| CVE-2026-12910 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 1 | MEDIUM | 5.4 | 25%ile | NVD | 2026-09-15 |
| CVE-2026-82837 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and | MEDIUM | 5.3 | 35%ile | NVD | 2026-09-15 |
| CVE-2025-8197 | Rejected reason: Maintainers have included reasons at https://gitlab.gnome.org/GNOME/libsoup/-/issues/465 | MEDIUM | 6.6 | — | Microsoft | 2025-07-08 |