Search CVE reports


Toggle filters

1 – 10 of 1462 results


CVE-2026-1751

Medium priority
Ignored

A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2025-4097

Medium priority
Ignored

(GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2026-24686

Medium priority
Needs evaluation

go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory....

1 affected package

golang-github-theupdateframework-go-tuf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-theupdateframework-go-tuf Needs evaluation Not in release
Show less packages

CVE-2025-11065

Medium priority
Needs evaluation

A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive...

1 affected package

golang-github-go-viper-mapstructure

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-viper-mapstructure Not in release Not in release
Show less packages

CVE-2026-24137

Medium priority
Needs evaluation

sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/client.go) supports caching target files to disk. It constructs a filesystem path...

1 affected package

golang-github-sigstore-sigstore

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-sigstore-sigstore Needs evaluation Not in release
Show less packages

CVE-2026-1102

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2026-0723

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an individual with existing knowledge of a victim's credential ID to...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2025-13928

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to cause a denial of service condition by...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2025-13335

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under certain circumstances could have allowed an authenticated user to create a denial...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2026-23992

Medium priority
Needs evaluation

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which...

1 affected package

golang-github-theupdateframework-go-tuf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-theupdateframework-go-tuf Needs evaluation Not in release
Show less packages