|
Proposal: Security-Only Backports for the Final Release of the Previous Major Version
|
|
1
|
18
|
September 16, 2026
|
|
Gitlab-secrets.json compromised after CVE-2026-85706
|
|
2
|
112
|
September 15, 2026
|
|
Orbit and API networking access
|
|
3
|
352
|
July 9, 2026
|
|
Orbit Tracer Security Agent - GitLab Duo Agent That Reduces Vulnerability Analysis from 4+ Hours to Minutes
|
|
0
|
189
|
June 24, 2026
|
|
Pentest scan says "Cookie without HttpOnly flag set" for /admin/usage_trends
|
|
2
|
286
|
May 20, 2026
|
|
Pentest scan says “OPTIONS method is enabled” for /api/v4/usage_data/track_event
|
|
2
|
204
|
May 20, 2026
|
|
Enforce Secret Push Protection on sub-group level
|
|
0
|
102
|
May 15, 2026
|
|
Encryption at rest of variables in database
|
|
4
|
600
|
April 30, 2026
|
|
Multiple CVEs nginx < 1.29.7 (Gitlab Omnibus v18.10.1-ee)
|
|
4
|
896
|
April 29, 2026
|
|
X-XSS- Protection is set to 0 in collect_events end point
|
|
3
|
569
|
April 17, 2026
|
|
How to prevent downstream .gitlab-ci.yml being modified by developers (role)?
|
|
1
|
248
|
April 2, 2026
|
|
Removing project from security montoring with more than 100 projects set
|
|
4
|
245
|
February 11, 2026
|
|
Semgrep.sarif: no such file or directory Error on Autoscaler executor
|
|
0
|
372
|
January 14, 2026
|
|
Again, locked due to an excessive number of unsuccessful sign in attempts
|
|
3
|
590
|
December 29, 2025
|
|
Account GITLAB has been locked due to an excessive number of unsuccessful sign in attempts' has been received
|
|
2
|
1889
|
December 22, 2025
|
|
Disabling GraphQL Introspection
|
|
4
|
2175
|
December 12, 2025
|
|
(SOLVED) Security issue? Getting strange "Unlock instructions" emails, are user emails leaked?
|
|
8
|
1055
|
December 10, 2025
|
|
Posting a comment with preformatted HTML code renders that HTML during submission
|
|
1
|
392
|
November 18, 2025
|
|
SAST jobs are not being executed
|
|
0
|
417
|
October 10, 2025
|
|
How to extend expiration of access tokens
|
|
11
|
34775
|
October 9, 2025
|
|
The status of issues changed from False positive to Needs triage automatically
|
|
0
|
211
|
October 4, 2025
|
|
Backups running slow in podman container gitlab-ee:18.2.4-ee.0; messages on host from permissive SEClinux Oralce Linux
|
|
0
|
81
|
September 8, 2025
|
|
Pentest report showing Excessive exposed headers and allowed http methods for graphql endpoint
|
|
1
|
246
|
September 2, 2025
|
|
It shouldn't be possible to change password without 2FA
|
|
0
|
86
|
August 25, 2025
|
|
Secret Detection started to fail today due to token appearing in .git/config
|
|
3
|
534
|
August 6, 2025
|
|
Turn-off "Unknown sign-in from new location"?
|
|
4
|
6626
|
August 4, 2025
|
|
How to setup user to audit all projects' settings (approval rules)?
|
|
0
|
97
|
July 17, 2025
|
|
Reporting malicious repository
|
|
0
|
125
|
June 21, 2025
|
|
Developer docs or information on how to create a new secrets provider?
|
|
0
|
404
|
May 3, 2025
|
|
CE GitLab contacting snowplowstg.trx.gitlab.net
|
|
2
|
513
|
May 11, 2025
|