gitlab-rails-ce-19.2

Direct Vulnerabilities

Known vulnerabilities in the gitlab-rails-ce-19.2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-395f-4hp3-45gv

<19.2.4-r6
  • L
CVE-2026-13311

<19.2.4-r6
  • L
GHSA-36jr-mh4h-2g58

<19.2.4-r5
  • L
Resource Exhaustion

<19.2.4-r4
  • L
GHSA-62hf-57xw-28j9

<19.2.4-r4
  • L
GHSA-p92q-9vqr-4j8v

<19.2.4-r4
  • C
Permissive Whitelist

<19.2.4-r4
  • L
Permissive Whitelist

<19.2.4-r4
  • L
GHSA-43fc-jf86-j433

<19.2.4-r4
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<19.2.4-r4
  • L
GHSA-w9j2-pvgh-6h63

<19.2.4-r4
  • L
GHSA-898c-q2cr-xwhg

<19.2.4-r4
  • L
GHSA-m7pr-hjqh-92cm

<19.2.4-r4
  • L
GHSA-xx6v-rp6x-q39c

<19.2.4-r4
  • L
GHSA-hfxv-24rg-xrqf

<19.2.4-r4
  • L
GHSA-35jp-ww65-95wh

<19.2.4-r4
  • H
Server-Side Request Forgery (SSRF)

<19.2.4-r4
  • C
Unintended Proxy or Intermediary ('Confused Deputy')

<19.2.4-r4
  • L
GHSA-pmwg-cvhr-8vh7

<19.2.4-r4
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.2.4-r4
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.2.4-r4
  • L
Information Exposure

<19.2.4-r4
  • L
GHSA-777c-7fjr-54vf

<19.2.4-r4
  • L
GHSA-3w6x-2g7m-8v23

<19.2.4-r4
  • L
Allocation of Resources Without Limits or Throttling

<19.2.4-r4
  • L
Allocation of Resources Without Limits or Throttling

<19.2.4-r4
  • L
GHSA-4hjh-wcwx-xvwj

<19.2.4-r4
  • L
GHSA-j5f8-grm9-p9fc

<19.2.4-r4
  • L
CRLF Injection

<19.2.4-r4
  • L
HTTP Response Splitting

<19.2.4-r4
  • L
GHSA-3g43-6gmg-66jw

<19.2.4-r4
  • H
Arbitrary Code Injection

<19.2.4-r4
  • L
GHSA-vf2m-468p-8v99

<19.2.4-r4
  • L
GHSA-q8qp-cvcw-x6jj

<19.2.4-r4
  • L
GHSA-xhjh-pmcv-23jw

<19.2.4-r4
  • L
GHSA-r4q5-vmmm-2653

<19.2.4-r4
  • L
Improper Encoding or Escaping of Output

<19.2.4-r4
  • L
Improper Check for Unusual or Exceptional Conditions

<19.2.4-r4
  • L
GHSA-3p68-rc4w-qgx5

<19.2.4-r4
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<19.2.4-r4
  • M
HTTP Response Splitting

<19.2.4-r4
  • L
GHSA-fvcv-3m26-pcqx

<19.2.4-r4
  • L
GHSA-445q-vr5w-6q77

<19.2.4-r4
  • H
Information Exposure

<19.2.4-r4
  • L
GHSA-pf86-5x62-jrwf

<19.2.4-r4
  • H
Uncontrolled Recursion

<19.2.4-r4
  • L
GHSA-6chq-wfr3-2hj9

<19.2.4-r4
  • L
Allocation of Resources Without Limits or Throttling

<19.2.4-r4
  • L
Allocation of Resources Without Limits or Throttling

<19.2.4-r4
  • L
GHSA-5c9x-8gcm-mpgx

<19.2.4-r4
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.2.4-r4
  • M
Improper Authentication

<19.2.4-r4
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<19.2.4-r3
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<19.2.4-r3
  • L
GHSA-2v37-7h3g-55p8

<19.2.4-r3
  • L
GHSA-28wg-ghj8-5hjv

<19.2.4-r3
  • L
XML Injection

<19.2.4-r1
  • L
GHSA-j759-j44w-7fr8

<19.2.4-r1
  • L
GHSA-wh4c-j3r5-mjhp

<19.2.4-r1
  • L
Uncontrolled Recursion

<19.2.4-r1
  • L
XML Injection

<19.2.4-r1
  • L
GHSA-2v35-w6hq-6mfw

<19.2.4-r1
  • L
GHSA-x6wf-f3px-wcqx

<19.2.4-r1
  • L
XML Injection

<19.2.4-r1
  • L
XML Injection

<19.2.4-r1
  • L
GHSA-f6ww-3ggp-fr8h

<19.2.4-r1
  • L
GHSA-2m8v-j782-fhvr

<19.2.2-r3
  • L
Improper Input Validation

<19.2.2-r3
  • L
GHSA-w8wr-v893-vjvp

<19.2.2-r2
  • M
Improper Handling of Unicode Encoding

<19.2.2-r2
  • M
Directory Traversal

<19.2.2-r2
  • L
GHSA-vmf3-w455-68vh

<19.2.2-r2
  • L
GHSA-9ppj-qmqm-q256

<19.2.2-r2
  • L
Incorrect Type Conversion or Cast

<19.2.2-r2
  • L
GHSA-gvwx-54wh-qm9j

<19.2.2-r2
  • L
Uncaught Exception

<19.2.2-r2
  • L
GHSA-83g3-92jg-28cx

<19.2.2-r2
  • L
Directory Traversal

<19.2.2-r2
  • L
CVE-2026-56859

<19.2.2-r2
  • L
GHSA-25mv-j2qr-v5jq

<19.2.2-r2
  • L
GHSA-qffp-2rhf-9h96

<19.2.2-r2
  • L
Allocation of Resources Without Limits or Throttling

<19.2.2-r2
  • H
Directory Traversal

<19.2.2-r2
  • L
GHSA-8qq5-rm4j-mr97

<19.2.2-r2
  • L
GHSA-xc2p-8ggw-6cr5

<19.2.2-r2
  • L
GHSA-r6q2-hw4h-h46w

<19.2.2-r2
  • L
GHSA-23hp-3jrh-7fpw

<19.2.2-r2
  • M
Directory Traversal

<19.2.2-r2
  • L
GHSA-34x7-hfp2-rc4v

<19.2.2-r2
  • L
GHSA-8x88-c5mf-7j5w

<19.2.2-r2
  • L
GHSA-76p8-fhrm-vpc7

<19.2.2-r2
  • L
CVE-2026-56860

<19.2.2-r2
  • L
Interpretation Conflict

<19.2.2-r2
  • L
CVE-2026-33818

<19.2.2-r2
  • M
Directory Traversal

<19.2.2-r2
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

<19.2.2-r2
  • L
CVE-2026-56862

<19.2.2-r2
  • L
GHSA-7qch-w8m5-g3h3

<19.2.2-r2
  • L
GHSA-qgq7-7hm3-q39j

<19.2.2-r1
  • L
Link Following

<19.2.2-r1
  • L
Directory Traversal

<19.2.2-r1
  • L
GHSA-hc8v-wwc9-vgxm

<19.2.2-r1
  • L
Uncontrolled Recursion

<19.2.1-r2
  • L
GHSA-25h7-pfq9-p65f

<19.2.1-r2
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.2.1-r1
  • L
GHSA-737v-mqg7-c878

<19.2.1-r1