gitlab
Safeguard articles tagged "gitlab" — guides, analysis, and best practices for software supply chain and application security.
20 articles
CVE-2021-22205: GitLab Community and Enterprise Editions Remote Code Execution Vulnerability
CVE-2021-22205 affects GitLab Community and Enterprise Editions and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2023-7028: GitLab Community and Enterprise Editions Improper Access Control Vulnerability
CVE-2023-7028 affects GitLab GitLab CE/EE and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-05-01.
CVE-2021-39935: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
CVE-2021-39935 affects GitLab Community and Enterprise Editions and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-03.
CVE-2021-22175: GitLab Server-Side Request Forgery (SSRF) Vulnerability
CVE-2021-22175 affects GitLab GitLab and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-18.
CVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
CVE-2026-85706 affects GitLab Community Edition and Enterprise Edition and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-09-11.
Two More GitLab SSRF Bugs, Reached Through Webhooks and the CI Lint API
An additional pair of GitLab server-side request forgery vulnerabilities, distinct from the CVE covered earlier in this series, both confirmed exploited within weeks of each other.
A CVSS 10.0 That Only Reads Files: GitLab CVE-2026-85706
An unauthenticated attacker reads arbitrary files from a GitLab server. There is no code execution, and it still scores 10.0 — because on a source host a read primitive is a credential incident.
GitLab Unauthenticated RCE via ExifTool Image Processing ...
CVE-2021-22205 let attackers gain unauthenticated RCE on self-hosted GitLab via ExifTool image parsing. Here's the affected versions, severity, timeline, and fixes.
GitLab Account Takeover via Password Reset (CVE-2023-7028) Explained
CVE-2023-7028 let attackers send GitLab password-reset links to an address they controlled — a zero-interaction account takeover scored 10.0. Here's the flaw and the fix.
GitLab ExifTool RCE (CVE-2021-22205) Explained
An unauthenticated attacker could run code on a GitLab server just by uploading an image. The bug was not in GitLab at all — it was in ExifTool. Here is the full story.
GitLab CI/CD Security Hardening for 2025
A practical hardening playbook for GitLab 17.8 covering runner isolation, OIDC federation, CI variable scoping, and protected branch enforcement.
GitLab CI Supply Chain Hardening Checklist 2026
A 2026 hardening checklist for GitLab CI: ID tokens, protected branches, runner isolation, included templates, and the controls that actually shrink blast radius.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.