Search CVE reports


Toggle filters

11 – 20 of 1478 results


CVE-2025-14594

Medium priority
Needs evaluation

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
gitlab-agent Needs evaluation Not in release
Show less packages

CVE-2025-14592

Medium priority
Needs evaluation

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
gitlab-agent Needs evaluation Not in release
Show less packages

CVE-2025-14560

Medium priority
Needs evaluation

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
gitlab-agent Needs evaluation Not in release
Show less packages

CVE-2025-12575

Medium priority
Needs evaluation

GitLab has remediated an issue in GitLab EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user with...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
gitlab-agent Needs evaluation Not in release
Show less packages

CVE-2025-12073

Medium priority
Needs evaluation

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an authenticated user to...

2 affected packages

gitlab, gitlab-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
gitlab-agent Needs evaluation Not in release
Show less packages

CVE-2026-25934

Medium priority
Needs evaluation

go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified....

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-git Needs evaluation Needs evaluation
Show less packages

CVE-2026-1751

Medium priority
Ignored

A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2026-24686

Medium priority
Needs evaluation

go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory....

1 affected package

golang-github-theupdateframework-go-tuf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-theupdateframework-go-tuf Needs evaluation Not in release
Show less packages

CVE-2025-11065

Medium priority
Needs evaluation

A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive...

1 affected package

golang-github-go-viper-mapstructure

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-viper-mapstructure Not in release Not in release
Show less packages

CVE-2026-24137

Medium priority
Needs evaluation

sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/client.go) supports caching target files to disk. It constructs a filesystem path...

1 affected package

golang-github-sigstore-sigstore

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-sigstore-sigstore Needs evaluation Not in release
Show less packages