CVE-2021-22205Critical· 10.0▾ Hadal⚠ Exploited in the wildPoC availableAn issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 55 · likelihood 19.9 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 4 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 1.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Nov 17, 2021
Last analysed / modified upstream
100%
Exploit-DB · 26 GitHub repos · Metasploit ×1 · Nuclei ×1 (last check)
Added to the CISA catalog on Nov 3, 2021. Federal remediation due Nov 17, 2021. View catalog ↗
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
gitlab >= 11.9.0, < 13.8.8gitlab >= 13.9.0, < 13.9.6gitlab >= 13.10.0, < 13.10.3Upgrade past the affected range:
gitlab 13.10.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85706Critical· 10.0GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…
CVE-2023-3519Critical· 9.8Unauthenticated remote code execution
CVE-2021-44529Critical· 9.8A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
CVE-2026-1516Medium· 5.7GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of user…
CVE-2025-14576High· 7.8Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick
CVE-2026-86341Medium· 4.4GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user with Owner or Maintainer permissions could have …