Safeguard
Tag

gitlab

Safeguard articles tagged "gitlab" — guides, analysis, and best practices for software supply chain and application security.

20 articles

Vulnerability Analysis

CVE-2021-22205: GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

CVE-2021-22205 affects GitLab Community and Enterprise Editions and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2023-7028: GitLab Community and Enterprise Editions Improper Access Control Vulnerability

CVE-2023-7028 affects GitLab GitLab CE/EE and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-05-01.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2021-39935: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

CVE-2021-39935 affects GitLab Community and Enterprise Editions and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-03.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2021-22175: GitLab Server-Side Request Forgery (SSRF) Vulnerability

CVE-2021-22175 affects GitLab GitLab and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-18.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

CVE-2026-85706 affects GitLab Community Edition and Enterprise Edition and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-09-11.

Sep 17, 20263 min read
Vulnerability Analysis

Two More GitLab SSRF Bugs, Reached Through Webhooks and the CI Lint API

An additional pair of GitLab server-side request forgery vulnerabilities, distinct from the CVE covered earlier in this series, both confirmed exploited within weeks of each other.

Sep 16, 20264 min read
Vulnerability Analysis

A CVSS 10.0 That Only Reads Files: GitLab CVE-2026-85706

An unauthenticated attacker reads arbitrary files from a GitLab server. There is no code execution, and it still scores 10.0 — because on a source host a read primitive is a credential incident.

Sep 16, 20266 min read
DevSecOps

GitLab Unauthenticated RCE via ExifTool Image Processing ...

CVE-2021-22205 let attackers gain unauthenticated RCE on self-hosted GitLab via ExifTool image parsing. Here's the affected versions, severity, timeline, and fixes.

Jul 25, 20267 min read
Vulnerability Analysis

GitLab Account Takeover via Password Reset (CVE-2023-7028) Explained

CVE-2023-7028 let attackers send GitLab password-reset links to an address they controlled — a zero-interaction account takeover scored 10.0. Here's the flaw and the fix.

Jul 5, 20265 min read
Vulnerability Analysis

GitLab ExifTool RCE (CVE-2021-22205) Explained

An unauthenticated attacker could run code on a GitLab server just by uploading an image. The bug was not in GitLab at all — it was in ExifTool. Here is the full story.

Jul 1, 20265 min read
DevSecOps

GitLab CI/CD Security Hardening for 2025

A practical hardening playbook for GitLab 17.8 covering runner isolation, OIDC federation, CI variable scoping, and protected branch enforcement.

Mar 29, 20265 min read
DevSecOps

GitLab CI Supply Chain Hardening Checklist 2026

A 2026 hardening checklist for GitLab CI: ID tokens, protected branches, runner isolation, included templates, and the controls that actually shrink blast radius.

Mar 19, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.