Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY1071 SECURITY RECORDS

GitLab

GitLab

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This CVE identity is linked to the Lifecycle record GitLab. Use that record for publisher support phases and retirement dates.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2025-14562 29 Jul 2026 GitLab: 10.6 < 19.0.5, 19.1 < 19.1.3, 19.2 < 19.2.1 Upgrade to versions 19.0.5, 19.1.3, 19.2.1 or above. Update reference ↗
CVE-2026-3093 29 Jul 2026 14.0 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-4672 29 Jul 2026 18.4 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-6267 29 Jul 2026 10.1.0 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-6336 29 Jul 2026 16.6 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-12436 29 Jul 2026 18.0 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-13113 29 Jul 2026 17.0 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-14341 29 Jul 2026 12.8 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-14351 29 Jul 2026 8.8 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-15077 29 Jul 2026 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-15831 29 Jul 2026 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-15975 29 Jul 2026 11.8 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-16553 29 Jul 2026 18.8 < 19.0.5; 19.1 < 19.1.3; 19.2 < 19.2.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-12506 8 Jul 2026 GitLab: 16.5 < 18.11.7, 19.0 < 19.0.4, 19.1 < 19.1.2 Upgrade to versions 18.11.7, 19.0.4, 19.1.2 or above. Update reference ↗
CVE-2026-6352 8 Jul 2026 18.2 < 18.11.7; 19.0 < 19.0.4; 19.1 < 19.1.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-6896 8 Jul 2026 13.11 < 18.11.7; 19.0 < 19.0.4; 19.1 < 19.1.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-7492 8 Jul 2026 9.1 < 18.11.7; 19.0 < 19.0.4; 19.1 < 19.1.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-8472 8 Jul 2026 18.9 < 18.11.7; 19.0 < 19.0.4; 19.1 < 19.1.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-11827 8 Jul 2026 9.5 < 18.11.7; 19.0 < 19.0.4; 19.1 < 19.1.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-13320 8 Jul 2026 15.7 < 18.11.7; 19.0 < 19.0.4; 19.1 < 19.1.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-10086 25 Jun 2026 16.4 < 18.11.6; 19.0 < 19.0.3; 19.1 < 19.1.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-0934 25 Jun 2026 17.9 < 18.11.6; 19.0 < 19.0.3; 19.1 < 19.1.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-1606 25 Jun 2026 14.8 < 18.11.6; 19.0 < 19.0.3; 19.1 < 19.1.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-2238 25 Jun 2026 17.5 < 18.11.6; 19.0 < 19.0.3; 19.1 < 19.1.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-3176 25 Jun 2026 18.6 < 18.11.6; 19.0 < 19.0.3; 19.1 < 19.1.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-5309 25 Jun 2026 18.6 < 18.11.6; 19.0 < 19.0.3; 19.1 < 19.1.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-5796 25 Jun 2026 13.6 < 18.11.6; 19.0 < 19.0.3; 19.1 < 19.1.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-5952 25 Jun 2026 17.11 < 18.11.6; 19.0 < 19.0.3; 19.1 < 19.1.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-8330 25 Jun 2026 9.3 < 18.11.6; 19.0 < 19.0.3; 19.1 < 19.1.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-10712 25 Jun 2026 18.10 < 18.11.6; 19.0 < 19.0.3; 19.1 < 19.1.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-11379 25 Jun 2026 13.11 < 18.11.6; 19.0 < 19.0.3; 19.1 < 19.1.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-12053 25 Jun 2026 19.1 < 19.1.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-12635 25 Jun 2026 8.3 < 18.11.6; 19.0 < 19.0.3; 19.1 < 19.1.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-1500 11 Jun 2026 17.10 < 18.10.8; 18.11 < 18.11.5; 19.0 < 19.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-3553 11 Jun 2026 12.0 < 18.10.8; 18.11 < 18.11.5; 19.0 < 19.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-6269 11 Jun 2026 15.10 < 18.10.8; 18.11 < 18.11.5; 19.0 < 19.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-6277 11 Jun 2026 13.9 < 18.10.8; 18.11 < 18.11.5; 19.0 < 19.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-6976 11 Jun 2026 15.9 < 18.10.8; 18.11 < 18.11.5; 19.0 < 19.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-7250 11 Jun 2026 12.10 < 18.10.8; 18.11 < 18.11.5; 19.0 < 19.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-8589 11 Jun 2026 13.1.4 < 18.10.8; 18.11 < 18.11.5; 19.0 < 19.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-9204 11 Jun 2026 18.10 < 18.10.8; 18.11 < 18.11.5; 19.0 < 19.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-9694 11 Jun 2026 15.9 < 18.10.8; 18.11 < 18.11.5; 19.0 < 19.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-10087 11 Jun 2026 17.1 < 18.10.8; 18.11 < 18.11.5; 19.0 < 19.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-10733 11 Jun 2026 17.0 < 18.10.8; 18.11 < 18.11.5; 19.0 < 19.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-9807 28 May 2026 18.9 < 18.10.7; 18.11 < 18.11.4; 19.0 < 19.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-1402 27 May 2026 17.1 < 18.10.7; 18.11 < 18.11.4; 19.0 < 19.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-2601 27 May 2026 11.5 < 18.10.7; 18.11 < 18.11.4; 19.0 < 19.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-4868 27 May 2026 18.8 < 18.10.7; 18.11 < 18.11.4; 19.0 < 19.0.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-5296 27 May 2026 18.7 < 18.10.7; 18.11 < 18.11.4; 19.0 < 19.0.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-6713 27 May 2026 18.2 < 18.10.7; 18.11 < 18.11.4; 19.0 < 19.0.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.