products / gitlab

GitLab

GitLab packages Git repository hosting, CI/CD, container registry, and security scanning in one Rails application. Core product vulnerabilities in NVD are attributed to gitlab:gitlab with explicit semver ranges for Community and Enterprise editions.

api usage

Querying GitLab

product sluggitlab
version format16.7.0, 17.2.0
bash
curl "https://api.attestd.io/v1/check?product=gitlab&version=16.7.0" \
  -H "Authorization: Bearer $ATTESTD_KEY"

16.7.0 is vulnerable to CVE-2023-7028 (CVSS 10.0, CISA KEV): an account takeover via user-controlled email addresses receiving password reset tokens without verification on secondary emails.

json
{
  "product": "gitlab",
  "version": "16.7.0",
  "supported": true,
  "risk_state": "critical",
  "risk_factors": [
    "active_exploitation",
    "remote_code_execution",
    "no_authentication_required",
    "internet_exposed_service",
    "patch_available"
  ],
  "actively_exploited": true,
  "remote_exploitable": true,
  "authentication_required": false,
  "patch_available": true,
  "fixed_version": "19.0.5",
  "confidence": 0.5,
  "cve_ids": [
    "CVE-2023-2030",
    "CVE-2023-3509",
    "CVE-2023-4812",
    "CVE-2023-4895",
    "CVE-2023-5117",
    "CVE-2023-5356",
    "CVE-2023-5612",
    "CVE-2023-5933",
    "CVE-2023-6159",
    "CVE-2023-6195",
    "CVE-2023-6371",
    "CVE-2023-6386",
    "CVE-2023-6477",
    "CVE-2023-6502",
    "CVE-2023-6678",
    "CVE-2023-6736",
    "CVE-2023-6840",
    "CVE-2023-6955",
    "CVE-2023-7028",
    "CVE-2023-7045",
    "CVE-2024-0199",
    "CVE-2024-0231",
    "CVE-2024-0402",
    "CVE-2024-0410",
    "CVE-2024-0456",
    "CVE-2024-0861",
    "CVE-2024-10043",
    "CVE-2024-10219",
    "CVE-2024-10307",
    "CVE-2024-10383",
    "CVE-2024-1066",
    "CVE-2024-10925",
    "CVE-2024-11274",
    "CVE-2024-11828",
    "CVE-2024-12093",
    "CVE-2024-1211",
    "CVE-2024-12292",
    "CVE-2024-12379",
    "CVE-2024-12380",
    "CVE-2024-12431",
    "CVE-2024-12570",
    "CVE-2024-12619",
    "CVE-2024-13041",
    "CVE-2024-13054",
    "CVE-2024-1347",
    "CVE-2024-1493",
    "CVE-2024-1495",
    "CVE-2024-1525",
    "CVE-2024-1539",
    "CVE-2024-1736",
    "CVE-2024-1816",
    "CVE-2024-1947",
    "CVE-2024-1963",
    "CVE-2024-2177",
    "CVE-2024-2279",
    "CVE-2024-2454",
    "CVE-2024-2651",
    "CVE-2024-2743",
    "CVE-2024-2800",
    "CVE-2024-2818",
    "CVE-2024-2829",
    "CVE-2024-2874",
    "CVE-2024-2878",
    "CVE-2024-2880",
    "CVE-2024-3035",
    "CVE-2024-3114",
    "CVE-2024-3115",
    "CVE-2024-3127",
    "CVE-2024-3303",
    "CVE-2024-3958",
    "CVE-2024-3959",
    "CVE-2024-3976",
    "CVE-2024-4006",
    "CVE-2024-4011",
    "CVE-2024-4024",
    "CVE-2024-4025",
    "CVE-2024-4099",
    "CVE-2024-4201",
    "CVE-2024-4207",
    "CVE-2024-4210",
    "CVE-2024-4278",
    "CVE-2024-4283",
    "CVE-2024-4472",
    "CVE-2024-4539",
    "CVE-2024-45409",
    "CVE-2024-4557",
    "CVE-2024-4597",
    "CVE-2024-4612",
    "CVE-2024-4660",
    "CVE-2024-4784",
    "CVE-2024-4835",
    "CVE-2024-4994",
    "CVE-2024-5005",
    "CVE-2024-5318",
    "CVE-2024-5423",
    "CVE-2024-5435",
    "CVE-2024-5528",
    "CVE-2024-5655",
    "CVE-2024-6324",
    "CVE-2024-6329",
    "CVE-2024-6356",
    "CVE-2024-6385",
    "CVE-2024-6502",
    "CVE-2024-6595",
    "CVE-2024-6678",
    "CVE-2024-6685",
    "CVE-2024-6826",
    "CVE-2024-7047",
    "CVE-2024-7057",
    "CVE-2024-7060",
    "CVE-2024-7091",
    "CVE-2024-7102",
    "CVE-2024-7296",
    "CVE-2024-7554",
    "CVE-2024-7610",
    "CVE-2024-7803",
    "CVE-2024-8041",
    "CVE-2024-8114",
    "CVE-2024-8124",
    "CVE-2024-8177",
    "CVE-2024-8186",
    "CVE-2024-8233",
    "CVE-2024-8237",
    "CVE-2024-8312",
    "CVE-2024-8631",
    "CVE-2024-8641",
    "CVE-2024-8647",
    "CVE-2024-8648",
    "CVE-2024-8650",
    "CVE-2024-8970",
    "CVE-2024-8974",
    "CVE-2024-8977",
    "CVE-2024-9163",
    "CVE-2024-9164",
    "CVE-2024-9367",
    "CVE-2024-9387",
    "CVE-2024-9512",
    "CVE-2024-9596",
    "CVE-2024-9623",
    "CVE-2024-9631",
    "CVE-2024-9633",
    "CVE-2024-9693",
    "CVE-2024-9773",
    "CVE-2024-9870",
    "CVE-2025-0186",
    "CVE-2025-0290",
    "CVE-2025-0362",
    "CVE-2025-0376",
    "CVE-2025-0475",
    "CVE-2025-0555",
    "CVE-2025-0639",
    "CVE-2025-0993",
    "CVE-2025-10004",
    "CVE-2025-10094",
    "CVE-2025-1042",
    "CVE-2025-10569",
    "CVE-2025-1072",
    "CVE-2025-10858",
    "CVE-2025-10871",
    "CVE-2025-11224",
    "CVE-2025-11246",
    "CVE-2025-11247",
    "CVE-2025-11447",
    "CVE-2025-11971",
    "CVE-2025-11974",
    "CVE-2025-11984",
    "CVE-2025-12029",
    "CVE-2025-1212",
    "CVE-2025-1250",
    "CVE-2025-12506",
    "CVE-2025-12555",
    "CVE-2025-12562",
    "CVE-2025-1257",
    "CVE-2025-12576",
    "CVE-2025-12664",
    "CVE-2025-12669",
    "CVE-2025-12697",
    "CVE-2025-12734",
    "CVE-2025-1278",
    "CVE-2025-1299",
    "CVE-2025-13436",
    "CVE-2025-13611",
    "CVE-2025-13874",
    "CVE-2025-13927",
    "CVE-2025-13929",
    "CVE-2025-14157",
    "CVE-2025-14511",
    "CVE-2025-14562",
    "CVE-2025-1477",
    "CVE-2025-1478",
    "CVE-2025-1516",
    "CVE-2025-1677",
    "CVE-2025-1763",
    "CVE-2025-1908",
    "CVE-2025-2246",
    "CVE-2025-2255",
    "CVE-2025-2256",
    "CVE-2025-2408",
    "CVE-2025-2443",
    "CVE-2025-2498",
    "CVE-2025-2614",
    "CVE-2025-2615",
    "CVE-2025-2853",
    "CVE-2025-2934",
    "CVE-2025-2937",
    "CVE-2025-3111",
    "CVE-2025-3279",
    "CVE-2025-3396",
    "CVE-2025-3525",
    "CVE-2025-3601",
    "CVE-2025-3922",
    "CVE-2025-3950",
    "CVE-2025-4097",
    "CVE-2025-4225",
    "CVE-2025-4439",
    "CVE-2025-4700",
    "CVE-2025-4979",
    "CVE-2025-5101",
    "CVE-2025-5819",
    "CVE-2025-5982",
    "CVE-2025-5996",
    "CVE-2025-6016",
    "CVE-2025-6171",
    "CVE-2025-6195",
    "CVE-2025-6769",
    "CVE-2025-7001",
    "CVE-2025-7337",
    "CVE-2025-7449",
    "CVE-2025-7691",
    "CVE-2025-7734",
    "CVE-2025-8014",
    "CVE-2025-8099",
    "CVE-2025-9484",
    "CVE-2025-9642",
    "CVE-2025-9825",
    "CVE-2025-9957",
    "CVE-2025-9958",
    "CVE-2026-0595",
    "CVE-2026-0602",
    "CVE-2026-0752",
    "CVE-2026-10086",
    "CVE-2026-1080",
    "CVE-2026-1090",
    "CVE-2026-1092",
    "CVE-2026-1102",
    "CVE-2026-11379",
    "CVE-2026-1182",
    "CVE-2026-11827",
    "CVE-2026-1184",
    "CVE-2026-1230",
    "CVE-2026-12635",
    "CVE-2026-1322",
    "CVE-2026-13320",
    "CVE-2026-1387",
    "CVE-2026-1388",
    "CVE-2026-14341",
    "CVE-2026-14351",
    "CVE-2026-1458",
    "CVE-2026-15975",
    "CVE-2026-1606",
    "CVE-2026-1659",
    "CVE-2026-1660",
    "CVE-2026-1662",
    "CVE-2026-1663",
    "CVE-2026-1732",
    "CVE-2026-1752",
    "CVE-2026-2370",
    "CVE-2026-2601",
    "CVE-2026-2726",
    "CVE-2026-2745",
    "CVE-2026-2845",
    "CVE-2026-2995",
    "CVE-2026-3074",
    "CVE-2026-3093",
    "CVE-2026-3160",
    "CVE-2026-3553",
    "CVE-2026-3848",
    "CVE-2026-4527",
    "CVE-2026-5262",
    "CVE-2026-5796",
    "CVE-2026-6063",
    "CVE-2026-6267",
    "CVE-2026-6269",
    "CVE-2026-6277",
    "CVE-2026-6336",
    "CVE-2026-6552",
    "CVE-2026-6883",
    "CVE-2026-6896",
    "CVE-2026-6976",
    "CVE-2026-7250",
    "CVE-2026-7481",
    "CVE-2026-7492",
    "CVE-2026-8144",
    "CVE-2026-8280",
    "CVE-2026-8330",
    "CVE-2026-8589",
    "CVE-2026-8716",
    "CVE-2026-9694"
  ],
  "cves": null,
  "max_epss": 0.94647,
  "last_updated": "2026-08-05T21:16:40.727763Z",
  "supply_chain": {
    "compromised": false,
    "sources": [],
    "malware_type": null,
    "description": null,
    "advisory_url": null,
    "compromised_at": null,
    "removed_at": null,
    "source_published_at": null,
    "observed_at": null,
    "ingested_at": null,
    "first_served_at": null,
    "provenance": null
  },
  "supply_chain_monitored": true,
  "typosquat": null
}
patched line

16.7.2 includes the fix for CVE-2023-7028 on the 16.7 stable train. Always map your install to the exact GitLab patch release in NVD.

bash
curl "https://api.attestd.io/v1/check?product=gitlab&version=19.0.5" \
  -H "Authorization: Bearer $ATTESTD_KEY"
notable cves

CVE history

CVEDescriptionAffectsCVSS
CVE-2023-7028KEV
Password reset sent to unverified emails (CISA KEV).GitLab CE/EE before patched Dec 2023 releases10.0
CVE-2024-6385
Pipeline job token reuse across projects.see NVD 17.x cuts9.6
CVE-2023-2825
Path traversal via nested repository import.see NVD10.0
related