VENDOR

GitLab vulnerabilities: CVEs, exploitation and patches

Every GitLab CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-19650
    GitLab GraphQL GET-request mutation execution vulnerability GitLab GitLab ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.1
  2. CVE-2026-10053
    GitLab package registry path traversal leads to authenticated remote code execution GitLab GitLab ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  3. CVE-2026-19478
    GitLab GraphQL directive lets unauthenticated users modify public projects GitLab GitLab ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.1
  4. CVE-2026-85706
    GitLab repository commits API path traversal lets unauthenticated read files GitLab Community Edition and Enterprise Edition ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 10
4 CVEs · page 1 of 1