Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: gitlab-ee

Found 67 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-9807
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 1 month, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    6 packages
    • gitlab-art
    • gitlab-duo
    • gitlab-kas
    • gitlab-ci-ls
    • gitlab-pages
    • gitlab-shell
Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed a blocked Project Access Token to continue accessing private resources due to incorrect authorization enforcement.

Affected products

GitLab
  • <18.10.7
  • <19.0.1
  • <18.11.4

Matching in nixpkgs

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Ignored packages (6)

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

Package maintainers

Published
Permalink CVE-2026-4868
8.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 1 month, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    45 packages
    • gitlab-art
    • ocamlPackages.gitlab-jsoo
    • ocamlPackages.gitlab-unix
    • rubyPackages.gitlab-markup
    • terraform-providers.gitlab
    • ocamlPackages_latest.gitlab
    • gitlab-elasticsearch-indexer
    • haskellPackages.gitlab-haskell
    • rubyPackages_3_3.gitlab-markup
    • rubyPackages_3_4.gitlab-markup
    • rubyPackages_4_0.gitlab-markup
    • python312Packages.mkdocs-gitlab
    • python312Packages.python-gitlab
    • python313Packages.mkdocs-gitlab
    • python313Packages.python-gitlab
    • python314Packages.mkdocs-gitlab
    • python314Packages.python-gitlab
    • ocamlPackages_latest.gitlab-jsoo
    • ocamlPackages_latest.gitlab-unix
    • terraform-providers.gitlabhq_gitlab
    • gnomeExtensions.gitlab-time-tracking
    • prometheus-gitlab-ci-pipelines-exporter
    • vscode-extensions.gitlab.gitlab-workflow
    • perlPackages.AlienBuildPluginDownloadGitLab
    • perl5Packages.AlienBuildPluginDownloadGitLab
    • perl538Packages.AlienBuildPluginDownloadGitLab
    • perl540Packages.AlienBuildPluginDownloadGitLab
    • gitlab-runner
    • gitlab-triage
    • gitlab-ci-local
    • gitlab-timelogs
    • gitlab-ci-linter
    • gitlab-workhorse
    • gitlab-release-cli
    • ocamlPackages.gitlab
    • vimPlugins.gitlab-vim
    • gitlab-container-registry
    • gitlab-duo
    • gitlab-kas
    • gitlab-ci-ls
    • gitlab-pages
    • gitlab-ee
    • danger-gitlab
    • gitlab-clippy
    • gitlab-shell
  • @LeSuisse restored package gitlab-ee
  • @LeSuisse ignored
    5 maintainers
    • @yayayayaka
    • @leona-ya
    • @talyz
    • @globin
    • @krav
    maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Authorization Bypass Through User-Controlled Key in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authenticated user to cause specific Duo AI workflows to run under another user's identity due to improper user identity resolution when triggering Duo AI workflow runners.

Affected products

GitLab
  • <18.10.7
  • <19.0.1
  • <18.11.4

Matching in nixpkgs

Ignored packages (44)

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Ignored maintainers (4)
Published
Permalink CVE-2026-5296
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 1 month, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    45 packages
    • gitlab-art
    • gitlab-duo
    • gitlab-pages
    • gitlab-shell
    • danger-gitlab
    • gitlab-clippy
    • gitlab-runner
    • gitlab-triage
    • gitlab-ci-local
    • gitlab-timelogs
    • gitlab-ci-linter
    • gitlab-kas
    • ocamlPackages_latest.gitlab
    • gitlab-elasticsearch-indexer
    • haskellPackages.gitlab-haskell
    • rubyPackages_3_3.gitlab-markup
    • rubyPackages_3_4.gitlab-markup
    • rubyPackages_4_0.gitlab-markup
    • python312Packages.mkdocs-gitlab
    • python312Packages.python-gitlab
    • python313Packages.mkdocs-gitlab
    • python313Packages.python-gitlab
    • python314Packages.mkdocs-gitlab
    • python314Packages.python-gitlab
    • ocamlPackages_latest.gitlab-jsoo
    • ocamlPackages_latest.gitlab-unix
    • terraform-providers.gitlabhq_gitlab
    • gnomeExtensions.gitlab-time-tracking
    • prometheus-gitlab-ci-pipelines-exporter
    • vscode-extensions.gitlab.gitlab-workflow
    • perlPackages.AlienBuildPluginDownloadGitLab
    • perl5Packages.AlienBuildPluginDownloadGitLab
    • perl538Packages.AlienBuildPluginDownloadGitLab
    • perl540Packages.AlienBuildPluginDownloadGitLab
    • terraform-providers.gitlab
    • rubyPackages.gitlab-markup
    • ocamlPackages.gitlab-unix
    • ocamlPackages.gitlab-jsoo
    • gitlab-container-registry
    • vimPlugins.gitlab-vim
    • ocamlPackages.gitlab
    • gitlab-release-cli
    • gitlab-ee
    • gitlab-workhorse
    • gitlab-ci-ls
  • @LeSuisse restored package gitlab-ee
  • @LeSuisse ignored
    5 maintainers
    • @yayayayaka
    • @leona-ya
    • @talyz
    • @globin
    • @krav
    maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Missing Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that when foundational flows were enabled at the group level, could have allowed an authenticated user with developer-role permissions to bypass flow restrictions under certain conditions.

Affected products

GitLab
  • <18.11.4
  • <19.0.1
  • <18.10.7

Matching in nixpkgs

Ignored packages (44)

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Ignored maintainers (4)
Published
Permalink CVE-2026-1402
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 1 month, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    44 packages
    • gitlab-ci-ls
    • gitlab-pages
    • gitlab-shell
    • danger-gitlab
    • gitlab-clippy
    • gitlab-runner
    • gitlab-triage
    • gitlab-ci-local
    • gitlab-timelogs
    • gitlab-ci-linter
    • gitlab-workhorse
    • gitlab-release-cli
    • ocamlPackages.gitlab
    • vimPlugins.gitlab-vim
    • gitlab-container-registry
    • ocamlPackages.gitlab-jsoo
    • ocamlPackages.gitlab-unix
    • rubyPackages.gitlab-markup
    • terraform-providers.gitlab
    • ocamlPackages_latest.gitlab
    • gitlab-elasticsearch-indexer
    • haskellPackages.gitlab-haskell
    • rubyPackages_3_3.gitlab-markup
    • rubyPackages_3_4.gitlab-markup
    • rubyPackages_4_0.gitlab-markup
    • python312Packages.mkdocs-gitlab
    • python312Packages.python-gitlab
    • python313Packages.mkdocs-gitlab
    • python313Packages.python-gitlab
    • python314Packages.mkdocs-gitlab
    • python314Packages.python-gitlab
    • ocamlPackages_latest.gitlab-jsoo
    • ocamlPackages_latest.gitlab-unix
    • terraform-providers.gitlabhq_gitlab
    • gnomeExtensions.gitlab-time-tracking
    • prometheus-gitlab-ci-pipelines-exporter
    • vscode-extensions.gitlab.gitlab-workflow
    • perlPackages.AlienBuildPluginDownloadGitLab
    • perl5Packages.AlienBuildPluginDownloadGitLab
    • perl538Packages.AlienBuildPluginDownloadGitLab
    • perl540Packages.AlienBuildPluginDownloadGitLab
    • gitlab-kas
    • gitlab-duo
    • gitlab-art
  • @LeSuisse ignored
    5 maintainers
    • @yayayayaka
    • @leona-ya
    • @globin
    • @talyz
    • @krav
    maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to cause denial of service due to insufficient validation.

Affected products

GitLab
  • <18.11.4
  • <19.0.1
  • <18.10.7

Matching in nixpkgs

Ignored packages (44)

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Ignored maintainers (4)
Published
Permalink CVE-2026-2601
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 1 month, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    44 packages
    • gitlab-ci-ls
    • gitlab-pages
    • gitlab-shell
    • danger-gitlab
    • gitlab-clippy
    • gitlab-runner
    • gitlab-triage
    • gitlab-ci-local
    • gitlab-timelogs
    • gitlab-ci-linter
    • gitlab-workhorse
    • gitlab-release-cli
    • ocamlPackages.gitlab
    • vimPlugins.gitlab-vim
    • gitlab-container-registry
    • ocamlPackages.gitlab-jsoo
    • ocamlPackages.gitlab-unix
    • rubyPackages.gitlab-markup
    • terraform-providers.gitlab
    • ocamlPackages_latest.gitlab
    • gitlab-elasticsearch-indexer
    • perl540Packages.AlienBuildPluginDownloadGitLab
    • perl538Packages.AlienBuildPluginDownloadGitLab
    • perl5Packages.AlienBuildPluginDownloadGitLab
    • rubyPackages_4_0.gitlab-markup
    • python312Packages.mkdocs-gitlab
    • python312Packages.python-gitlab
    • python313Packages.mkdocs-gitlab
    • python313Packages.python-gitlab
    • python314Packages.mkdocs-gitlab
    • python314Packages.python-gitlab
    • ocamlPackages_latest.gitlab-jsoo
    • ocamlPackages_latest.gitlab-unix
    • terraform-providers.gitlabhq_gitlab
    • gnomeExtensions.gitlab-time-tracking
    • prometheus-gitlab-ci-pipelines-exporter
    • vscode-extensions.gitlab.gitlab-workflow
    • perlPackages.AlienBuildPluginDownloadGitLab
    • rubyPackages_3_4.gitlab-markup
    • rubyPackages_3_3.gitlab-markup
    • gitlab-kas
    • gitlab-duo
    • gitlab-art
    • haskellPackages.gitlab-haskell
  • @LeSuisse ignored
    5 maintainers
    • @yayayayaka
    • @leona-ya
    • @talyz
    • @krav
    • @globin
    maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Missing Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to access sensitive deployment data on projects due to improper authorization checks.

Affected products

GitLab
  • <18.10.7
  • <19.0.1
  • <18.11.4

Matching in nixpkgs

Ignored packages (44)

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Ignored maintainers (4)
Published
Permalink CVE-2026-8716
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 1 month, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    44 packages
    • gitlab-art
    • danger-gitlab
    • gitlab-clippy
    • gitlab-runner
    • gitlab-triage
    • gitlab-ci-local
    • gitlab-timelogs
    • gitlab-ci-linter
    • gitlab-workhorse
    • gitlab-release-cli
    • ocamlPackages.gitlab
    • vimPlugins.gitlab-vim
    • gitlab-container-registry
    • ocamlPackages.gitlab-jsoo
    • ocamlPackages.gitlab-unix
    • rubyPackages.gitlab-markup
    • terraform-providers.gitlab
    • ocamlPackages_latest.gitlab
    • gitlab-elasticsearch-indexer
    • haskellPackages.gitlab-haskell
    • rubyPackages_3_3.gitlab-markup
    • rubyPackages_3_4.gitlab-markup
    • rubyPackages_4_0.gitlab-markup
    • python312Packages.mkdocs-gitlab
    • python312Packages.python-gitlab
    • python313Packages.mkdocs-gitlab
    • python313Packages.python-gitlab
    • python314Packages.mkdocs-gitlab
    • python314Packages.python-gitlab
    • ocamlPackages_latest.gitlab-jsoo
    • ocamlPackages_latest.gitlab-unix
    • terraform-providers.gitlabhq_gitlab
    • gnomeExtensions.gitlab-time-tracking
    • prometheus-gitlab-ci-pipelines-exporter
    • vscode-extensions.gitlab.gitlab-workflow
    • perlPackages.AlienBuildPluginDownloadGitLab
    • perl5Packages.AlienBuildPluginDownloadGitLab
    • perl538Packages.AlienBuildPluginDownloadGitLab
    • perl540Packages.AlienBuildPluginDownloadGitLab
    • gitlab-kas
    • gitlab-duo
    • gitlab-pages
    • gitlab-shell
    • gitlab-ci-ls
  • @LeSuisse ignored
    5 maintainers
    • @yayayayaka
    • @leona-ya
    • @talyz
    • @krav
    • @globin
    maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Use of Incorrectly-Resolved Name or Reference in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended.

Affected products

GitLab
  • <18.10.7
  • <19.0.1
  • <18.11.4

Matching in nixpkgs

Ignored packages (44)

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Ignored maintainers (4)
Published
Permalink CVE-2026-6713
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 1 month, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    44 packages
    • terraform-providers.gitlabhq_gitlab
    • ocamlPackages_latest.gitlab-unix
    • ocamlPackages_latest.gitlab-jsoo
    • python314Packages.python-gitlab
    • python314Packages.mkdocs-gitlab
    • gnomeExtensions.gitlab-time-tracking
    • prometheus-gitlab-ci-pipelines-exporter
    • vscode-extensions.gitlab.gitlab-workflow
    • perlPackages.AlienBuildPluginDownloadGitLab
    • perl5Packages.AlienBuildPluginDownloadGitLab
    • perl538Packages.AlienBuildPluginDownloadGitLab
    • perl540Packages.AlienBuildPluginDownloadGitLab
    • rubyPackages.gitlab-markup
    • ocamlPackages.gitlab-unix
    • gitlab-container-registry
    • vimPlugins.gitlab-vim
    • ocamlPackages.gitlab
    • gitlab-kas
    • gitlab-ci-ls
    • gitlab-pages
    • gitlab-shell
    • danger-gitlab
    • gitlab-clippy
    • gitlab-runner
    • gitlab-triage
    • gitlab-ci-local
    • gitlab-timelogs
    • python312Packages.python-gitlab
    • python313Packages.mkdocs-gitlab
    • python312Packages.mkdocs-gitlab
    • rubyPackages_4_0.gitlab-markup
    • rubyPackages_3_4.gitlab-markup
    • haskellPackages.gitlab-haskell
    • ocamlPackages_latest.gitlab
    • ocamlPackages.gitlab-jsoo
    • gitlab-release-cli
    • gitlab-art
    • gitlab-ci-linter
    • gitlab-workhorse
    • terraform-providers.gitlab
    • gitlab-elasticsearch-indexer
    • rubyPackages_3_3.gitlab-markup
    • python313Packages.python-gitlab
    • gitlab-duo
  • @LeSuisse ignored
    5 maintainers
    • @globin
    • @talyz
    • @krav
    • @leona-ya
    • @yayayayaka
    maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an unauthorized user to enumerate private projects due to incorrect authorization checks.

Affected products

GitLab
  • <18.10.7
  • <19.0.1
  • <18.11.4

Matching in nixpkgs

Ignored packages (44)

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Ignored maintainers (4)
Published
Permalink CVE-2026-7481
8.7 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    44 packages
    • gitlab-art
    • gitlab-duo
    • gitlab-kas
    • gitlab-ci-ls
    • gitlab-pages
    • gitlab-shell
    • danger-gitlab
    • gitlab-clippy
    • gitlab-runner
    • gitlab-triage
    • gitlab-ci-local
    • gitlab-timelogs
    • gitlab-ci-linter
    • gitlab-workhorse
    • gitlab-release-cli
    • ocamlPackages.gitlab
    • vimPlugins.gitlab-vim
    • gitlab-container-registry
    • ocamlPackages.gitlab-jsoo
    • ocamlPackages.gitlab-unix
    • rubyPackages.gitlab-markup
    • terraform-providers.gitlab
    • ocamlPackages_latest.gitlab
    • gitlab-elasticsearch-indexer
    • haskellPackages.gitlab-haskell
    • rubyPackages_3_3.gitlab-markup
    • rubyPackages_3_4.gitlab-markup
    • rubyPackages_4_0.gitlab-markup
    • python312Packages.mkdocs-gitlab
    • python312Packages.python-gitlab
    • python313Packages.mkdocs-gitlab
    • python313Packages.python-gitlab
    • python314Packages.mkdocs-gitlab
    • python314Packages.python-gitlab
    • ocamlPackages_latest.gitlab-jsoo
    • ocamlPackages_latest.gitlab-unix
    • terraform-providers.gitlabhq_gitlab
    • gnomeExtensions.gitlab-time-tracking
    • prometheus-gitlab-ci-pipelines-exporter
    • vscode-extensions.gitlab.gitlab-workflow
    • perlPackages.AlienBuildPluginDownloadGitLab
    • perl5Packages.AlienBuildPluginDownloadGitLab
    • perl538Packages.AlienBuildPluginDownloadGitLab
    • perl540Packages.AlienBuildPluginDownloadGitLab
  • @LeSuisse ignored
    5 maintainers
    • @globin
    • @krav
    • @leona-ya
    • @yayayayaka
    • @talyz
    maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to execute arbitrary JavaScript in other users' browsers due to improper input sanitization.

Affected products

GitLab
  • <18.11.3
  • <18.10.6
  • <18.9.7

Matching in nixpkgs

Ignored packages (44)

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Ignored maintainers (4)
Published
Permalink CVE-2026-6883
2.6 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    44 packages
    • gitlab-art
    • gitlab-duo
    • gitlab-kas
    • gitlab-ci-ls
    • gitlab-pages
    • gitlab-shell
    • danger-gitlab
    • gitlab-clippy
    • gitlab-runner
    • gitlab-triage
    • gitlab-ci-local
    • gitlab-timelogs
    • gitlab-ci-linter
    • gitlab-workhorse
    • gitlab-release-cli
    • ocamlPackages.gitlab
    • vimPlugins.gitlab-vim
    • gitlab-container-registry
    • ocamlPackages.gitlab-jsoo
    • ocamlPackages.gitlab-unix
    • rubyPackages.gitlab-markup
    • terraform-providers.gitlab
    • ocamlPackages_latest.gitlab
    • gitlab-elasticsearch-indexer
    • haskellPackages.gitlab-haskell
    • rubyPackages_3_3.gitlab-markup
    • rubyPackages_3_4.gitlab-markup
    • rubyPackages_4_0.gitlab-markup
    • python312Packages.mkdocs-gitlab
    • python312Packages.python-gitlab
    • python313Packages.mkdocs-gitlab
    • python313Packages.python-gitlab
    • python314Packages.mkdocs-gitlab
    • python314Packages.python-gitlab
    • ocamlPackages_latest.gitlab-jsoo
    • ocamlPackages_latest.gitlab-unix
    • terraform-providers.gitlabhq_gitlab
    • gnomeExtensions.gitlab-time-tracking
    • prometheus-gitlab-ci-pipelines-exporter
    • vscode-extensions.gitlab.gitlab-workflow
    • perlPackages.AlienBuildPluginDownloadGitLab
    • perl5Packages.AlienBuildPluginDownloadGitLab
    • perl538Packages.AlienBuildPluginDownloadGitLab
    • perl540Packages.AlienBuildPluginDownloadGitLab
  • @LeSuisse ignored
    5 maintainers
    • @talyz
    • @leona-ya
    • @globin
    • @krav
    • @yayayayaka
    maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Missing Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to bypass merge request approval requirements due to improper cleanup of orphaned policy records.

Affected products

GitLab
  • <18.11.3
  • <18.10.6
  • <18.9.7

Matching in nixpkgs

Ignored packages (44)

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Ignored maintainers (4)
Published
Permalink CVE-2026-1659
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    44 packages
    • gitlab-art
    • gitlab-duo
    • gitlab-kas
    • gitlab-ci-ls
    • gitlab-pages
    • gitlab-shell
    • danger-gitlab
    • gitlab-clippy
    • gitlab-runner
    • gitlab-triage
    • gitlab-ci-local
    • gitlab-timelogs
    • gitlab-ci-linter
    • gitlab-workhorse
    • gitlab-release-cli
    • ocamlPackages.gitlab
    • vimPlugins.gitlab-vim
    • gitlab-container-registry
    • ocamlPackages.gitlab-jsoo
    • ocamlPackages.gitlab-unix
    • rubyPackages.gitlab-markup
    • terraform-providers.gitlab
    • ocamlPackages_latest.gitlab
    • gitlab-elasticsearch-indexer
    • haskellPackages.gitlab-haskell
    • rubyPackages_3_3.gitlab-markup
    • rubyPackages_3_4.gitlab-markup
    • rubyPackages_4_0.gitlab-markup
    • python312Packages.mkdocs-gitlab
    • python312Packages.python-gitlab
    • python313Packages.mkdocs-gitlab
    • python313Packages.python-gitlab
    • python314Packages.mkdocs-gitlab
    • python314Packages.python-gitlab
    • ocamlPackages_latest.gitlab-jsoo
    • ocamlPackages_latest.gitlab-unix
    • terraform-providers.gitlabhq_gitlab
    • gnomeExtensions.gitlab-time-tracking
    • prometheus-gitlab-ci-pipelines-exporter
    • vscode-extensions.gitlab.gitlab-workflow
    • perlPackages.AlienBuildPluginDownloadGitLab
    • perl5Packages.AlienBuildPluginDownloadGitLab
    • perl538Packages.AlienBuildPluginDownloadGitLab
    • perl540Packages.AlienBuildPluginDownloadGitLab
  • @LeSuisse ignored
    5 maintainers
    • @globin
    • @yayayayaka
    • @krav
    • @talyz
    • @leona-ya
    maintainer.ignore
  • @LeSuisse ignored reference HackerOne…
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted requests due to insufficient input validation.

Affected products

GitLab
  • <18.11.3
  • <18.10.6
  • <18.9.7

Matching in nixpkgs

Ignored packages (44)

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Ignored maintainers (4)