Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: gitlab

Found 99 matching suggestions

View:
Compact
Detailed
Published
Permalink CVE-2026-3073
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 3 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored reference HackerOne…
  • @LeSuisse ignored
    44 packages
    • gitlab-art
    • gitlab-duo
    • gitlab-kas
    • gitlab-ci-ls
    • gitlab-pages
    • gitlab-shell
    • danger-gitlab
    • gitlab-clippy
    • gitlab-runner
    • gitlab-triage
    • gitlab-ci-local
    • gitlab-timelogs
    • gitlab-ci-linter
    • gitlab-workhorse
    • gitlab-release-cli
    • ocamlPackages.gitlab
    • vimPlugins.gitlab-vim
    • gitlab-container-registry
    • ocamlPackages.gitlab-jsoo
    • ocamlPackages.gitlab-unix
    • rubyPackages.gitlab-markup
    • terraform-providers.gitlab
    • ocamlPackages_latest.gitlab
    • gitlab-elasticsearch-indexer
    • haskellPackages.gitlab-haskell
    • rubyPackages_3_3.gitlab-markup
    • rubyPackages_3_4.gitlab-markup
    • rubyPackages_4_0.gitlab-markup
    • python312Packages.mkdocs-gitlab
    • python312Packages.python-gitlab
    • python313Packages.mkdocs-gitlab
    • python313Packages.python-gitlab
    • python314Packages.mkdocs-gitlab
    • python314Packages.python-gitlab
    • ocamlPackages_latest.gitlab-jsoo
    • ocamlPackages_latest.gitlab-unix
    • terraform-providers.gitlabhq_gitlab
    • gnomeExtensions.gitlab-time-tracking
    • prometheus-gitlab-ci-pipelines-exporter
    • vscode-extensions.gitlab.gitlab-workflow
    • perlPackages.AlienBuildPluginDownloadGitLab
    • perl5Packages.AlienBuildPluginDownloadGitLab
    • perl538Packages.AlienBuildPluginDownloadGitLab
    • perl540Packages.AlienBuildPluginDownloadGitLab
  • @LeSuisse ignored
    5 maintainers
    • @talyz
    • @leona-ya
    • @krav
    • @globin
    • @yayayayaka
    maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Authorization Bypass Through User-Controlled Key in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to bypass PyPI package protection rules and upload restricted packages due to improper authorization checks.

Affected products

GitLab
  • <18.9.7
  • <18.11.3
  • <18.10.6

Matching in nixpkgs

Ignored packages (44)

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-ci-local

Run gitlab pipelines locally as shell executor or docker executor

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Ignored maintainers (4)
Published
Permalink CVE-2025-13874
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 3 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    45 packages
    • gitlab-art
    • gitlab-duo
    • gitlab-kas
    • gitlab-ci-ls
    • gitlab-pages
    • gitlab-shell
    • danger-gitlab
    • gitlab-clippy
    • gitlab-runner
    • gitlab-triage
    • gitlab-ci-local
    • gitlab-timelogs
    • gitlab-ci-linter
    • gitlab-workhorse
    • gitlab-release-cli
    • ocamlPackages.gitlab
    • vimPlugins.gitlab-vim
    • gitlab-container-registry
    • ocamlPackages.gitlab-jsoo
    • ocamlPackages.gitlab-unix
    • rubyPackages.gitlab-markup
    • terraform-providers.gitlab
    • ocamlPackages_latest.gitlab
    • gitlab-elasticsearch-indexer
    • haskellPackages.gitlab-haskell
    • rubyPackages_3_3.gitlab-markup
    • rubyPackages_3_4.gitlab-markup
    • rubyPackages_4_0.gitlab-markup
    • python312Packages.mkdocs-gitlab
    • python312Packages.python-gitlab
    • python313Packages.mkdocs-gitlab
    • python313Packages.python-gitlab
    • python314Packages.mkdocs-gitlab
    • python314Packages.python-gitlab
    • ocamlPackages_latest.gitlab-jsoo
    • ocamlPackages_latest.gitlab-unix
    • terraform-providers.gitlabhq_gitlab
    • gnomeExtensions.gitlab-time-tracking
    • prometheus-gitlab-ci-pipelines-exporter
    • vscode-extensions.gitlab.gitlab-workflow
    • perlPackages.AlienBuildPluginDownloadGitLab
    • gitlab-ee
    • perl540Packages.AlienBuildPluginDownloadGitLab
    • perl538Packages.AlienBuildPluginDownloadGitLab
    • perl5Packages.AlienBuildPluginDownloadGitLab
  • @LeSuisse restored package gitlab-ee
  • @LeSuisse ignored
    5 maintainers
    • @talyz
    • @leona-ya
    • @yayayayaka
    • @krav
    • @globin
    maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Authorization Bypass Through User-Controlled Key in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with Guest permissions to view issues in projects they were not authorized to access.

Affected products

GitLab
  • <18.9.7
  • <18.11.3
  • <18.10.6

Matching in nixpkgs

Ignored packages (44)

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-ci-local

Run gitlab pipelines locally as shell executor or docker executor

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Ignored maintainers (4)
Published
Permalink CVE-2026-7471
3.5 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 3 months, 4 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    44 packages
    • gitlab-art
    • gitlab-duo
    • gitlab-kas
    • gitlab-ci-ls
    • gitlab-pages
    • gitlab-shell
    • danger-gitlab
    • gitlab-clippy
    • gitlab-runner
    • gitlab-triage
    • gitlab-ci-local
    • gitlab-timelogs
    • gitlab-ci-linter
    • gitlab-workhorse
    • gitlab-release-cli
    • ocamlPackages.gitlab
    • vimPlugins.gitlab-vim
    • gitlab-container-registry
    • ocamlPackages.gitlab-jsoo
    • ocamlPackages.gitlab-unix
    • rubyPackages.gitlab-markup
    • terraform-providers.gitlab
    • ocamlPackages_latest.gitlab
    • gitlab-elasticsearch-indexer
    • haskellPackages.gitlab-haskell
    • rubyPackages_3_3.gitlab-markup
    • rubyPackages_3_4.gitlab-markup
    • rubyPackages_4_0.gitlab-markup
    • python312Packages.mkdocs-gitlab
    • python312Packages.python-gitlab
    • python313Packages.mkdocs-gitlab
    • python313Packages.python-gitlab
    • python314Packages.mkdocs-gitlab
    • python314Packages.python-gitlab
    • ocamlPackages_latest.gitlab-jsoo
    • ocamlPackages_latest.gitlab-unix
    • terraform-providers.gitlabhq_gitlab
    • gnomeExtensions.gitlab-time-tracking
    • prometheus-gitlab-ci-pipelines-exporter
    • vscode-extensions.gitlab.gitlab-workflow
    • perlPackages.AlienBuildPluginDownloadGitLab
    • perl5Packages.AlienBuildPluginDownloadGitLab
    • perl538Packages.AlienBuildPluginDownloadGitLab
    • perl540Packages.AlienBuildPluginDownloadGitLab
  • @LeSuisse ignored
    5 maintainers
    • @globin
    • @krav
    • @yayayayaka
    • @leona-ya
    • @talyz
    maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Server-Side Request Forgery (SSRF) in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with control of a virtual registry upstream to make requests to internal hosts due to improper validation.

Affected products

GitLab
  • <18.9.7
  • <18.11.3
  • <18.10.6

Matching in nixpkgs

Ignored packages (44)

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-ci-local

Run gitlab pipelines locally as shell executor or docker executor

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Ignored maintainers (4)
Untriaged
Permalink CVE-2026-1338
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 3 months, 4 weeks ago Activity log
  • Created suggestion
Authorization Bypass Through User-Controlled Key in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to delete protected container registry tags due to improper authorization checks.

Affected products

GitLab
  • <18.9.7
  • <18.11.3
  • <18.10.6

Matching in nixpkgs

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-ci-local

Run gitlab pipelines locally as shell executor or docker executor

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Untriaged
Permalink CVE-2025-14870
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 3 months, 4 weeks ago Activity log
  • Created suggestion
Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted JSON payloads due to insufficient input validation.

Affected products

GitLab
  • <18.11.3
  • <18.9.7
  • <18.10.6

Matching in nixpkgs

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-ci-local

Run gitlab pipelines locally as shell executor or docker executor

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Untriaged
Permalink CVE-2026-6335
5.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 3 months, 4 weeks ago Activity log
  • Created suggestion
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.3 that under certain conditions could have allowed an authenticated user to execute arbitrary code in another user's browser session due to improper sanitization.

Affected products

GitLab
  • <18.11.3

Matching in nixpkgs

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-ci-local

Run gitlab pipelines locally as shell executor or docker executor

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Untriaged
Permalink CVE-2026-3074
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 3 months, 4 weeks ago Activity log
  • Created suggestion
Authorization Bypass Through User-Controlled Key in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to download private debugging symbols from inaccessible projects due to improper access control.

Affected products

GitLab
  • <18.11.3
  • <18.9.7
  • <18.10.6

Matching in nixpkgs

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-ci-local

Run gitlab pipelines locally as shell executor or docker executor

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Untriaged
Permalink CVE-2026-6063
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 3 months, 4 weeks ago Activity log
  • Created suggestion
Authorization Bypass Through User-Controlled Key in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that under certain conditions could have allowed an authenticated user with developer-role permissions to remove code owner approval rules from merge requests due to improper access control.

Affected products

GitLab
  • <18.11.3
  • <18.9.7
  • <18.10.6

Matching in nixpkgs

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-ci-local

Run gitlab pipelines locally as shell executor or docker executor

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Untriaged
Permalink CVE-2025-12669
5.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 3 months, 4 weeks ago Activity log
  • Created suggestion
Improper Control of Generation of Code ('Code Injection') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to inject HTML and JavaScript into email notifications sent to other users due to improper input sanitization.

Affected products

GitLab
  • <18.9.7
  • <18.11.3
  • <18.10.6

Matching in nixpkgs

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-ci-local

Run gitlab pipelines locally as shell executor or docker executor

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers

Untriaged
Permalink CVE-2026-2900
2.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 3 months, 4 weeks ago Activity log
  • Created suggestion
Missing Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that when instance-level approval rule editing prevention was enabled, could have allowed an authenticated user with Maintainer permissions to modify or delete project approval rules due to missing authorization checks.

Affected products

GitLab
  • <18.11.3
  • <18.9.7
  • <18.10.6

Matching in nixpkgs

pkgs.gitlab-art

Pull cross-project Gitlab artifact dependencies

pkgs.danger-gitlab

Gem that exists to ensure all dependencies are set up for Danger with GitLab

pkgs.gitlab-clippy

Convert clippy warnings into GitLab Code Quality report

pkgs.gitlab-ci-local

Run gitlab pipelines locally as shell executor or docker executor

pkgs.gitlab-timelogs

CLI utility to support you with your time logs in GitLab

Package maintainers