2026 (3)
| N° | CVE | Severity | Description | Links |
|---|---|---|---|---|
| 38 | CVE-2026-15423 | Improper Authorization issue in CI/CD pipeline API impacts GitLab CE/EE | GitLab Patch Release 19.2.2 · NVD | |
| 37 | CVE-2026-1101 | Denial of Service issue in GitLab EE GraphQL SBOM API - GitLab Patch Release | GitLab Patch Release 18.10.3 · Advisory GHSA-ffch-rw3v-4mvx · NVD | |
| 36 | CVE-2026-1388 | Regular Expression Denial of Service issue in GitLab merge requests - GitLab Patch Release | GitLab Patch Release 18.9.1 · Advisory GHSA-35pf-5r93-c5jc · NVD |
2025 (7)
| N° | CVE | Severity | Description | Links |
|---|---|---|---|---|
| 35 | CVE-2025-12576 | Denial of Service issue in GitLab EE webhook endpoint | GitLab Patch Release 18.9.2 · NVD | |
| 34 | CVE-2025-13690 | Denial of Service issue in GitLab EE webhook custom headers - H1 Report | GitLab Patch Release 18.9.2 · Advisory GHSA-mgcq-rqq2-gc5f · NVD | |
| 33 | CVE-2025-13335 | Crafted wiki file may lead to endless server-side redirections in GitLab EE | BleepingComputer · GitLab Patch Release 18.8.2 | |
| 32 | CVE-2025-0673 | An attacker can trigger an infinite redirect loop, leading to a denial of service condition in GitLab EE | BleepingComputer · GitLab Patch Release 18.0.2 | |
| 31 | GHSA-6p2v-wcv8-8j6w | Arbitrary File Read by Copy as a Curl command in Caido Plugin Exploit Generator | GitHub | |
| 30 | CVE-2025-0549 | Partial Bypass for Device OAuth flow using Cross Window Forgery in GitLab EE | GitLab Patch Release 17.11.2 | |
| 29 | CVE-2025-31116 | SSRF on assetlinks_check with DNS Rebinding in MobSF | Advisory GHSA-fcfq-m8p6-gw56 · GitLab · NVD |
2024 (13)
| N° | CVE | Severity | Description | Links |
|---|---|---|---|---|
| 28 | CVE-2024-13054 | Denial of Service Due to Inefficient Processing of Untrusted Input in GitLab EE - GitLab Patch Release | GitLab Patch Release 17.9.2 · NVD | |
| 27 | CVE-2024-12379 | Denial of Service due to Unbounded Symbol Creation via the scopes parameter in a Personal Access Token in GitLab EE | GitLab Patch Release 17.8.2 · NVD | |
| 26 | CVE-2024-47830 | Server side request forgery via /_next/image endpoint in Plane | GitHub · NVD · Anquanke (Chinese) | |
| 25 | CVE-2024-8124 | Denial of Service via sending a large glm_source parameter in GitLab EE | GitLab Critical Patch Release 17.3.2 · NVD | |
| 24 | CVE-2024-45412 | Potential Denial of Service due to the One Million Unicode Characters attack in Yeti Platform | GitHub · NVD | |
| 23 | CVE-2024-35231 | Denial of Service due to the unconstrained value of the incoming "profiler_runs" parameter in Rack::Contrib | Advisory GHSA-8c8q-2xw3-j869 · NVD | |
| 22 | CVE-2024-1211 | Require confirmation before linking JWT identity in GitLab EE | GitLab Patch Release 16.11.2 · NVD | |
| 21 | GHSA-9gw7-hxgx-f6rv | Malicious Long Unicode filenames may cause an Application-level Denial of Service in FAME (Cert SG) | GitHub | |
| 20 | CVE-2024-32874 | Malicious Long Unicode filenames may cause Multiple Application-level Denial of Service in Frigate | GitHub · NVD | |
| 19 | CVE-2024-0081 | Unicode use in a user-controlled filename may cause a server-side DoS in NVIDIA NeMo - Nvidia Acknowledgement | GitHub · NVD · NVIDIA Acknowledgements | |
| 18 | CVE-2024-24759 | Bypass SSRF Protection with DNS Rebinding in MindsDB | GitHub · GitLab · NVD | |
| 17 | CVE-2024-23826 | Uploading an image with a specific filename causes a server-side DoS in SPbU SE Site | GitHub · NVD | |
| 16 | CVE-2024-21623 | Arbitrary Expression Injection in GitHub workflow leads to Command execution & leaking secrets in OTClient | GitHub · NVD · Offensive360 |
2023 (11)
| N° | CVE | Severity | Description | Links |
|---|---|---|---|---|
| 15 | CVE-2023-52081 | Late-Unicode normalization vulnerability in ffcss | GitHub · NVD | |
| 14 | CVE-2023-41889 | Late-Unicode normalization vulnerability in Shirasagi - advisory | GitHub · NVD | |
| 13 | CVE-2023-42183 | A Post-Unicode Normalization Vulnerability in LOCKSS | GitHub · NVD · CVE.org | |
| 12 | GHSA-373w-rj84-pv6x | Hostname blocklist does not block FQDNs in safeurl-python | GitHub · GitLab | |
| 11 | CVE-2023-35932 | Configuration Injection due to unsanitized user input in jcvi | GitHub · NVD · CVE.org | |
| 10 | CVE-2023-31131 | Arbitrary File Write (path traversal) when extracting tar files within GPPKGs in Greenplum DB | GitHub · NVD | |
| 9 | CVE-2023-30620 | Arbitrary File Write when Extracting a Remotely retrieved Tarball using Tarfile.extractall() in MindsDB |
GitHub · NVD · Snyk | |
| 8 | CVE-2022-23522 | Arbitrary File Write when Extracting Tarballs using shutil.unpack_archive() in MindsDB |
GitHub · NVD · CVE.org | |
| 7 | CVE-2023-25803 | Directory Traversal vulnerability leading to inclusion of server-side files in Roxy-WI | GitHub · NVD · CVE.org | |
| 6 | CVE-2023-25802 | Path Traversal via unneutralized dir/../filename sequences in Roxy-WI |
GitHub · NVD | |
| 5 | CVE-2023-25804 | Limited Path Traversal in name parameter in Roxy-WI | GitHub · NVD · CVE.org |
2022 (4)
| N° | CVE | Severity | Description | Links |
|---|---|---|---|---|
| 4 | huntr-309725a2 | Potential TarSlip (CWE-59 Link Following) when extracting a remote archive without checksum verification in scikit-learn | SecurityLab | |
| 3 | CVE-2022-23530 | GuardDog vulnerable to arbitrary file write when scanning a specially-crafted remote PyPI package | GitHub · SecurityLab · GitLab · NVD · Snyk · PyPI | |
| 2 | CVE-2022-3607 | ZipSlip Symlink variant allows to read any file within OctoPrint Box | Advisory GHSA-rj5f-vm79-5j84 · NVD | |
| 1 | CVE-2022-1993 | Path Traversal vulnerability on the endpoint '/info/refs' in Gogs | Advisory GHSA-6vcc-v9vw-g2x5 · Gogs Changelog · NVD |
Reach out for a security code review — DM me on X (Twitter).




