VENDOR
GitLab vulnerabilities: CVEs, exploitation and patches
Every GitLab CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.
-
CVE-2026-19650
GitLab GraphQL GET-request mutation execution vulnerabilityHIGH 7.1
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-10053
GitLab package registry path traversal leads to authenticated remote code executionHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-19478
GitLab GraphQL directive lets unauthenticated users modify public projectsCRITICAL 9.1
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-85706
GitLab repository commits API path traversal lets unauthenticated read filesCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
No CVEs on this page match the filters.
4 CVEs · page 1 of 1