Gitlab

Gitlab

Top 1K site
Bounty RecognitionPartial Safe Harbor

Program Details

Handle
gitlab
Managed
Yes

Response Metrics

Response Time
3 days
Bounty Time
999 days
Resolution Time
1677 days
Response Efficiency
71%

Scope (19 targets)

web: 10 other: 9

Bounty splitting: Yes

In Scope

  • *.gitlab.net web bounty-eligible
  • *.gitlab.org web bounty-eligible
  • *.gitlap.com web bounty-eligible
  • GitLab for Jira Cloud other bounty-eligible
  • Other non-production infrastructure other bounty-eligible
  • Your Own GitLab Instance other bounty-eligible
  • about.gitlab.com web bounty-eligible
  • advisories.gitlab.com web bounty-eligible
  • customers.gitlab.com web bounty-eligible
  • design.gitlab.com web bounty-eligible
  • docs.gitlab.com web bounty-eligible
  • gitlab.com web bounty-eligible
  • https://gitlab.com/gitlab-org/gitaly other bounty-eligible
  • https://gitlab.com/gitlab-org/gitlab other bounty-eligible
  • https://gitlab.com/gitlab-org/gitlab-pages other bounty-eligible
  • https://gitlab.com/gitlab-org/gitlab-runner other bounty-eligible
  • https://gitlab.com/gitlab-org/gitlab-shell other bounty-eligible
  • https://gitlab.com/gitlab-org/gitlab-vscode-extension other bounty-eligible
  • registry.gitlab.com web bounty-eligible

Out of Scope

*.gitlab-private.org, *.gitlab.cn, *.runway.gitlab.net, *.service-now.com, alerts.gitlab.com, aptly.gitlab.com, dashboards.gitlab.com, federal-support.gitlab.com, forum.gitlab.com, gitlab.biterg.io, gitlabdemo.cloud, gitlabsandbox.net, gitlabtraining.cloud, https://gitlab.com/gitlab-org/cli/, https://gitlab.com/gitlab-org/opstrace/opstrace, https://gitlab.com/gitlab-org/opstrace/opstrace-ui, ir.gitlab.com, levelup.gitlab.com, packages.gitlab.com, partners.gitlab.com, shop.gitlab.com, status.gitlab.com, support.gitlab.com, translate.gitlab.com, us-federal-gitlab.com

Known Exploited Vulnerabilities 5CVEs

1 linked to ransomware campaigns

  • CVE-2026-85706Community Edition and Enterprise EditionSep 11, 202614.6% EPSS

    GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.

  • CVE-2021-22175GitLabFeb 18, 202653.4% EPSS

    GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.

  • CVE-2021-39935Community and Enterprise EditionsFeb 3, 202635.6% EPSS

    GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.

  • CVE-2023-7028GitLab CE/EEMay 1, 202494.6% EPSS

    GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.

  • CVE-2021-22205Community and Enterprise EditionsNov 3, 202199.7% EPSS

    GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.