products / gitlab
GitLab
GitLab packages Git repository hosting, CI/CD, container registry, and security scanning in one Rails application. Core product vulnerabilities in NVD are attributed to gitlab:gitlab with explicit semver ranges for Community and Enterprise editions.
api usage
Querying GitLab
product slug
gitlabversion format
16.7.0, 17.2.0bash
curl "https://api.attestd.io/v1/check?product=gitlab&version=16.7.0" \
-H "Authorization: Bearer $ATTESTD_KEY"16.7.0 is vulnerable to CVE-2023-7028 (CVSS 10.0, CISA KEV): an account takeover via user-controlled email addresses receiving password reset tokens without verification on secondary emails.
json
{
"product": "gitlab",
"version": "16.7.0",
"supported": true,
"risk_state": "critical",
"risk_factors": [
"active_exploitation",
"remote_code_execution",
"no_authentication_required",
"internet_exposed_service",
"patch_available"
],
"actively_exploited": true,
"remote_exploitable": true,
"authentication_required": false,
"patch_available": true,
"fixed_version": "19.0.5",
"confidence": 0.5,
"cve_ids": [
"CVE-2023-2030",
"CVE-2023-3509",
"CVE-2023-4812",
"CVE-2023-4895",
"CVE-2023-5117",
"CVE-2023-5356",
"CVE-2023-5612",
"CVE-2023-5933",
"CVE-2023-6159",
"CVE-2023-6195",
"CVE-2023-6371",
"CVE-2023-6386",
"CVE-2023-6477",
"CVE-2023-6502",
"CVE-2023-6678",
"CVE-2023-6736",
"CVE-2023-6840",
"CVE-2023-6955",
"CVE-2023-7028",
"CVE-2023-7045",
"CVE-2024-0199",
"CVE-2024-0231",
"CVE-2024-0402",
"CVE-2024-0410",
"CVE-2024-0456",
"CVE-2024-0861",
"CVE-2024-10043",
"CVE-2024-10219",
"CVE-2024-10307",
"CVE-2024-10383",
"CVE-2024-1066",
"CVE-2024-10925",
"CVE-2024-11274",
"CVE-2024-11828",
"CVE-2024-12093",
"CVE-2024-1211",
"CVE-2024-12292",
"CVE-2024-12379",
"CVE-2024-12380",
"CVE-2024-12431",
"CVE-2024-12570",
"CVE-2024-12619",
"CVE-2024-13041",
"CVE-2024-13054",
"CVE-2024-1347",
"CVE-2024-1493",
"CVE-2024-1495",
"CVE-2024-1525",
"CVE-2024-1539",
"CVE-2024-1736",
"CVE-2024-1816",
"CVE-2024-1947",
"CVE-2024-1963",
"CVE-2024-2177",
"CVE-2024-2279",
"CVE-2024-2454",
"CVE-2024-2651",
"CVE-2024-2743",
"CVE-2024-2800",
"CVE-2024-2818",
"CVE-2024-2829",
"CVE-2024-2874",
"CVE-2024-2878",
"CVE-2024-2880",
"CVE-2024-3035",
"CVE-2024-3114",
"CVE-2024-3115",
"CVE-2024-3127",
"CVE-2024-3303",
"CVE-2024-3958",
"CVE-2024-3959",
"CVE-2024-3976",
"CVE-2024-4006",
"CVE-2024-4011",
"CVE-2024-4024",
"CVE-2024-4025",
"CVE-2024-4099",
"CVE-2024-4201",
"CVE-2024-4207",
"CVE-2024-4210",
"CVE-2024-4278",
"CVE-2024-4283",
"CVE-2024-4472",
"CVE-2024-4539",
"CVE-2024-45409",
"CVE-2024-4557",
"CVE-2024-4597",
"CVE-2024-4612",
"CVE-2024-4660",
"CVE-2024-4784",
"CVE-2024-4835",
"CVE-2024-4994",
"CVE-2024-5005",
"CVE-2024-5318",
"CVE-2024-5423",
"CVE-2024-5435",
"CVE-2024-5528",
"CVE-2024-5655",
"CVE-2024-6324",
"CVE-2024-6329",
"CVE-2024-6356",
"CVE-2024-6385",
"CVE-2024-6502",
"CVE-2024-6595",
"CVE-2024-6678",
"CVE-2024-6685",
"CVE-2024-6826",
"CVE-2024-7047",
"CVE-2024-7057",
"CVE-2024-7060",
"CVE-2024-7091",
"CVE-2024-7102",
"CVE-2024-7296",
"CVE-2024-7554",
"CVE-2024-7610",
"CVE-2024-7803",
"CVE-2024-8041",
"CVE-2024-8114",
"CVE-2024-8124",
"CVE-2024-8177",
"CVE-2024-8186",
"CVE-2024-8233",
"CVE-2024-8237",
"CVE-2024-8312",
"CVE-2024-8631",
"CVE-2024-8641",
"CVE-2024-8647",
"CVE-2024-8648",
"CVE-2024-8650",
"CVE-2024-8970",
"CVE-2024-8974",
"CVE-2024-8977",
"CVE-2024-9163",
"CVE-2024-9164",
"CVE-2024-9367",
"CVE-2024-9387",
"CVE-2024-9512",
"CVE-2024-9596",
"CVE-2024-9623",
"CVE-2024-9631",
"CVE-2024-9633",
"CVE-2024-9693",
"CVE-2024-9773",
"CVE-2024-9870",
"CVE-2025-0186",
"CVE-2025-0290",
"CVE-2025-0362",
"CVE-2025-0376",
"CVE-2025-0475",
"CVE-2025-0555",
"CVE-2025-0639",
"CVE-2025-0993",
"CVE-2025-10004",
"CVE-2025-10094",
"CVE-2025-1042",
"CVE-2025-10569",
"CVE-2025-1072",
"CVE-2025-10858",
"CVE-2025-10871",
"CVE-2025-11224",
"CVE-2025-11246",
"CVE-2025-11247",
"CVE-2025-11447",
"CVE-2025-11971",
"CVE-2025-11974",
"CVE-2025-11984",
"CVE-2025-12029",
"CVE-2025-1212",
"CVE-2025-1250",
"CVE-2025-12506",
"CVE-2025-12555",
"CVE-2025-12562",
"CVE-2025-1257",
"CVE-2025-12576",
"CVE-2025-12664",
"CVE-2025-12669",
"CVE-2025-12697",
"CVE-2025-12734",
"CVE-2025-1278",
"CVE-2025-1299",
"CVE-2025-13436",
"CVE-2025-13611",
"CVE-2025-13874",
"CVE-2025-13927",
"CVE-2025-13929",
"CVE-2025-14157",
"CVE-2025-14511",
"CVE-2025-14562",
"CVE-2025-1477",
"CVE-2025-1478",
"CVE-2025-1516",
"CVE-2025-1677",
"CVE-2025-1763",
"CVE-2025-1908",
"CVE-2025-2246",
"CVE-2025-2255",
"CVE-2025-2256",
"CVE-2025-2408",
"CVE-2025-2443",
"CVE-2025-2498",
"CVE-2025-2614",
"CVE-2025-2615",
"CVE-2025-2853",
"CVE-2025-2934",
"CVE-2025-2937",
"CVE-2025-3111",
"CVE-2025-3279",
"CVE-2025-3396",
"CVE-2025-3525",
"CVE-2025-3601",
"CVE-2025-3922",
"CVE-2025-3950",
"CVE-2025-4097",
"CVE-2025-4225",
"CVE-2025-4439",
"CVE-2025-4700",
"CVE-2025-4979",
"CVE-2025-5101",
"CVE-2025-5819",
"CVE-2025-5982",
"CVE-2025-5996",
"CVE-2025-6016",
"CVE-2025-6171",
"CVE-2025-6195",
"CVE-2025-6769",
"CVE-2025-7001",
"CVE-2025-7337",
"CVE-2025-7449",
"CVE-2025-7691",
"CVE-2025-7734",
"CVE-2025-8014",
"CVE-2025-8099",
"CVE-2025-9484",
"CVE-2025-9642",
"CVE-2025-9825",
"CVE-2025-9957",
"CVE-2025-9958",
"CVE-2026-0595",
"CVE-2026-0602",
"CVE-2026-0752",
"CVE-2026-10086",
"CVE-2026-1080",
"CVE-2026-1090",
"CVE-2026-1092",
"CVE-2026-1102",
"CVE-2026-11379",
"CVE-2026-1182",
"CVE-2026-11827",
"CVE-2026-1184",
"CVE-2026-1230",
"CVE-2026-12635",
"CVE-2026-1322",
"CVE-2026-13320",
"CVE-2026-1387",
"CVE-2026-1388",
"CVE-2026-14341",
"CVE-2026-14351",
"CVE-2026-1458",
"CVE-2026-15975",
"CVE-2026-1606",
"CVE-2026-1659",
"CVE-2026-1660",
"CVE-2026-1662",
"CVE-2026-1663",
"CVE-2026-1732",
"CVE-2026-1752",
"CVE-2026-2370",
"CVE-2026-2601",
"CVE-2026-2726",
"CVE-2026-2745",
"CVE-2026-2845",
"CVE-2026-2995",
"CVE-2026-3074",
"CVE-2026-3093",
"CVE-2026-3160",
"CVE-2026-3553",
"CVE-2026-3848",
"CVE-2026-4527",
"CVE-2026-5262",
"CVE-2026-5796",
"CVE-2026-6063",
"CVE-2026-6267",
"CVE-2026-6269",
"CVE-2026-6277",
"CVE-2026-6336",
"CVE-2026-6552",
"CVE-2026-6883",
"CVE-2026-6896",
"CVE-2026-6976",
"CVE-2026-7250",
"CVE-2026-7481",
"CVE-2026-7492",
"CVE-2026-8144",
"CVE-2026-8280",
"CVE-2026-8330",
"CVE-2026-8589",
"CVE-2026-8716",
"CVE-2026-9694"
],
"cves": null,
"max_epss": 0.94647,
"last_updated": "2026-08-05T21:16:40.727763Z",
"supply_chain": {
"compromised": false,
"sources": [],
"malware_type": null,
"description": null,
"advisory_url": null,
"compromised_at": null,
"removed_at": null,
"source_published_at": null,
"observed_at": null,
"ingested_at": null,
"first_served_at": null,
"provenance": null
},
"supply_chain_monitored": true,
"typosquat": null
}patched line
16.7.2 includes the fix for CVE-2023-7028 on the 16.7 stable train. Always map your install to the exact GitLab patch release in NVD.
bash
curl "https://api.attestd.io/v1/check?product=gitlab&version=19.0.5" \
-H "Authorization: Bearer $ATTESTD_KEY"notable cves
CVE history
| CVE | Description | Affects | CVSS |
|---|---|---|---|
CVE-2023-7028KEV | Password reset sent to unverified emails (CISA KEV). | GitLab CE/EE before patched Dec 2023 releases | 10.0 |
CVE-2024-6385 | Pipeline job token reuse across projects. | see NVD 17.x cuts | 9.6 |
CVE-2023-2825 | Path traversal via nested repository import. | see NVD | 10.0 |
related