Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/gitlab-org/gitlab

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.

Join the discussion
0

An authorization vulnerability in GitLab CE/EE allows authenticated users with developer role to modify certain package registry metadata without maintainer-level permissions. This issue affects versions from 17.6 up to but not including 19.0.6, 19.1 up to but not including 19.1.4, and 19.2 up to but not including 19.2.2. The flaw was due to improper authorization checks and has been remediated by GitLab.

Join the discussion

A cross-site scripting (XSS) vulnerability was identified in GitLab CE/EE versions from 19.2 up to but not including 19.2.2. This issue involved improper sanitization of HTML content rendered in a CI job modal, which under certain conditions could allow an authenticated user with developer-role permissions to escalate privileges. The vulnerability has been remediated in version 19.2.2.

Join the discussion
0

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute CI/CD pipelines on a protected branch without the required push permissions due to improper authorization in pipeline reference validation.

Join the discussion

Multiple vulnerabilities affecting GitLab Community Edition and Enterprise Edition versions from 12.7 up to but not including 18.10.7, 18.11 up to but not including 18.11.4, and 19.0 up to but not including 19.0.1 have been identified and fixed. These include issues related to improper resource management and authorization flaws across six CVEs including CVE-2026-1402. No known exploits in the wild have been reported. The product is not a cloud service. A patch is available for these vulnerabilities.

Join the discussion

A vulnerability in GitLab CE/EE versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 could allow unauthorized users to view project import source information due to a missing authorization check. This issue has been remediated in the specified fixed versions.

Join the discussion

A vulnerability in GitLab Enterprise Edition versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 could allow sensitive information disclosure due to improper handling of upstream requests in virtual registries. This issue has been remediated by GitLab in the specified fixed versions. The vulnerability is classified as CWE-522 and has a CVSS 3.1 vector indicating network attack vector, low attack complexity, low privileges required, no user interaction, unchanged scope, limited confidentiality impact, no integrity impact, and low availability impact. No known exploits in the wild have been reported.

Join the discussion

GitLab Enterprise Edition versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 contain a vulnerability that allows an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token generation. This issue affects integrity but does not impact confidentiality or availability. The vulnerability has been remediated in versions 19.1.3 and 19.2.1. No known exploits have been reported in the wild.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Package: pkg:github/gitlab-org/gitlab
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses