gitlab-rails-ce-19.3

Direct Vulnerabilities

Known vulnerabilities in the gitlab-rails-ce-19.3 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Resource Exhaustion

<19.3.2-r3
  • L
GHSA-7jxh-36q5-gcqv

<19.3.2-r3
  • L
Directory Traversal

<19.3.2-r2
  • L
GHSA-82fw-gwwq-j7x9

<19.3.2-r2
  • L
Inefficient Regular Expression Complexity

<19.3.2-r1
  • L
GHSA-2wm5-q62r-hmrv

<19.3.2-r1
  • H
Uncontrolled Recursion

<19.3.1-r6
  • L
GHSA-3mcp-22mf-vrw3

<19.3.1-r6
  • L
GHSA-pxg6-pf52-xh8x

<19.3.1-r8
  • L
CVE-2024-47764

<19.3.1-r8
  • L
CVE-2025-57352

<19.3.1-r9
  • L
GHSA-rx8g-88g5-qh64

<19.3.1-r9
  • H
Arbitrary Code Injection

<19.3.1-r6
  • L
GHSA-79cf-xcqc-c78w

<19.3.1-r6
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r6
  • H
Out-of-bounds Write

<19.3.1-r6
  • M
Exposed Dangerous Method or Function

<19.3.1-r6
  • L
CVE-2026-82562

<19.3.1-r6
  • L
Integer Overflow or Wraparound

<19.3.1-r6
  • L
CVE-2025-7339

<19.3.1-r6
  • L
CVE-2026-82417

<19.3.1-r6
  • L
GHSA-952p-6rrq-rcjv

<19.3.1-r6
  • H
Allocation of Resources Without Limits or Throttling

<19.3.1-r6
  • L
GHSA-p67v-3w7g-wjg7

<19.3.1-r6
  • L
CVE-2024-4068

<19.3.1-r6
  • L
GHSA-vj76-c3g6-qr5v

<19.3.1-r6
  • L
GHSA-v422-hmwv-36x6

<19.3.1-r6
  • L
GHSA-x2f5-4prf-w687

<19.3.1-r6
  • M
Improper Resource Shutdown or Release

<19.3.1-r10
  • C
Directory Traversal

<19.3.1-r6
  • L
GHSA-pmv8-rq9r-6j72

<19.3.1-r6
  • L
OS Command Injection

<19.3.1-r6
  • L
Cross-site Scripting (XSS)

<19.3.1-r6
  • L
GHSA-2x63-gw47-w4mm

<19.3.1-r6
  • L
GHSA-23c5-xmqv-rm74

<19.3.1-r6
  • L
GHSA-v56q-mh7h-f735

<19.3.1-r6
  • M
Resource Exhaustion

<19.3.1-r6
  • L
GHSA-c4c3-pg64-4m4v

<19.3.1-r6
  • L
GHSA-7q8q-rj6j-mhjq

<19.3.1-r6
  • L
Algorithmic Complexity

<19.3.1-r6
  • L
CVE-2026-13311

<19.3.1-r6
  • L
GHSA-rgw5-rvv9-x895

<19.3.1-r6
  • L
CVE-2026-12590

<19.3.1-r6
  • L
GHSA-395f-4hp3-45gv

<19.3.1-r6
  • L
Resource Exhaustion

<19.3.1-r6
  • L
Uncaught Exception

<19.3.1-r6
  • L
Directory Traversal

<19.3.1-r11
  • L
Heap-based Buffer Overflow

<19.3.1-r6
  • L
Inefficient Regular Expression Complexity

<19.3.1-r6
  • L
GHSA-3rrr-jr9j-h3q3

<19.3.1-r6
  • L
GHSA-vpq2-c234-7xj6

<19.3.1-r6
  • L
GHSA-xvcm-6775-5m9r

<19.3.1-r6
  • L
GHSA-8cj5-5rvv-wf4v

<19.3.1-r6
  • L
GHSA-xj6q-8x83-jv6g

<19.3.1-r6
  • L
GHSA-7p8r-x3mc-p8w7

<19.3.1-r6
  • L
Cross-site Scripting (XSS)

<19.3.1-r6
  • L
CVE-2026-76172

<19.3.1-r6
  • L
GHSA-xcj9-5m2h-648r

<19.3.1-r6
  • L
GHSA-qjx8-664m-686j

<19.3.1-r6
  • L
GHSA-gcfj-64vw-6mp9

<19.3.1-r6
  • H
Permissive Whitelist

<19.3.1-r6
  • L
GHSA-42h9-826w-cgv3

<19.3.1-r6
  • L
GHSA-wf6x-7x77-mvgw

<19.3.1-r6
  • L
GHSA-3ppc-4f35-3m26

<19.3.1-r6
  • L
GHSA-8whx-365g-h9vv

<19.3.1-r6
  • L
CVE-2026-8723

<19.3.1-r6
  • H
Resource Exhaustion

<19.3.1-r6
  • L
Inefficient Regular Expression Complexity

<19.3.1-r6
  • L
GHSA-9wjq-cp2p-hrgf

<19.3.1-r6
  • L
GHSA-hmw2-7cc7-3qxx

<19.3.1-r6
  • L
GHSA-76c9-3jph-rj3q

<19.3.1-r6
  • L
GHSA-48rx-c7pg-q66r

<19.3.1-r6
  • H
Information Exposure

<19.3.1-r6
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

<19.3.1-r6
  • L
GHSA-6v5v-wf23-fmfq

<19.3.1-r6
  • L
Server-Side Request Forgery (SSRF)

<19.3.1-r6
  • L
GHSA-4c8g-83qw-93j6

<19.3.1-r6
  • L
GHSA-fqj3-h9pc-443h

<19.3.1-r6
  • L
GHSA-58qx-3vcg-4xpx

<19.3.1-r6
  • L
CVE-2026-78662

<19.3.1-r6
  • L
GHSA-xxjr-mmjv-4gpg

<19.3.1-r6
  • H
Use of Uninitialized Resource

<19.3.1-r6
  • L
GHSA-5v8h-3h3q-446p

<19.3.1-r6
  • L
Arbitrary Code Injection

<19.3.1-r6
  • L
GHSA-5c6j-r48x-rmvq

<19.3.1-r6
  • L
GHSA-6gmq-8vp8-gcm6

<19.3.1-r6
  • L
GHSA-7r86-cg39-jmmj

<19.3.1-r6
  • L
GHSA-4v9v-hfq4-rm2v

<19.3.1-r6
  • L
CVE-2025-15284

<19.3.1-r6
  • M
CVE-2026-2950

<19.3.1-r6
  • L
GHSA-mwf2-3pr3-8698

<19.3.1-r6
  • L
GHSA-pjwm-pj3p-43mv

<19.3.1-r6
  • L
GHSA-33ph-fccm-39pj

<19.3.1-r6
  • H
Directory Traversal

<19.3.1-r6
  • L
GHSA-4mjr-xmp4-gh2g

<19.3.1-r6
  • L
GHSA-qx2v-qp2m-jg93

<19.3.1-r6
  • L
GHSA-ghcm-xqfw-q4vr

<19.3.1-r6
  • M
Directory Traversal

<19.3.1-r6
  • L
GHSA-37ch-88jc-xwx2

<19.3.1-r6
  • L
CVE-2026-56855

<19.3.1-r6
  • H
Resource Exhaustion

<19.3.1-r6
  • L
GHSA-phwj-rprq-35pp

<19.3.1-r6
  • L
GHSA-jxxr-4gwj-5jf2

<19.3.1-r6
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r6
  • L
GHSA-f23m-r3pf-42rh

<19.3.1-r6
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r6
  • L
CVE-2026-18446

<19.3.1-r6
  • L
CVE-2026-41149

<19.3.1-r6
  • L
GHSA-ph9p-34f9-6g65

<19.3.1-r6
  • L
Improper Encoding or Escaping of Output

<19.3.1-r6
  • L
CVE-2026-16221

<19.3.1-r6
  • L
CVE-2026-6322

<19.3.1-r6
  • M
Arbitrary Code Injection

<19.3.1-r6
  • L
GHSA-c83g-rgw3-j3cx

<19.3.1-r6
  • L
GHSA-v245-v573-v5vm

<19.3.1-r6
  • L
Directory Traversal

<19.3.1-r6
  • L
GHSA-rhh3-jpg6-66xh

<19.3.1-r6
  • M
CVE-2024-4067

<19.3.1-r6
  • L
Cross-site Scripting (XSS)

<19.3.1-r6
  • L
GHSA-87f9-hvmw-gh4p

<19.3.1-r6
  • L
GHSA-jr5f-v2jv-69x6

<19.3.1-r6
  • L
GHSA-v2hh-gcrm-f6hx

<19.3.1-r6
  • L
GHSA-r5fr-rjxr-66jc

<19.3.1-r6
  • L
GHSA-f4gw-2p7v-4548

<19.3.1-r6
  • M
CVE-2026-9595

<19.3.1-r6
  • M
Cross-site Request Forgery (CSRF)

<19.3.1-r6
  • L
GHSA-q3j6-qgpj-74h6

<19.3.1-r6
  • L
GHSA-p498-v437-472g

<19.3.1-r6
  • L
GHSA-6rw7-vpxm-498p

<19.3.1-r6
  • L
GHSA-73wf-gq98-2v4g

<19.3.1-r6
  • L
GHSA-67mh-4wv8-2f99

<19.3.1-r6
  • L
Server-Side Request Forgery (SSRF)

<19.3.1-r6
  • L
Uncaught Exception

<19.3.1-r6
  • L
GHSA-hcpx-6fm6-wx23

<19.3.1-r6
  • L
GHSA-wf5p-g6vw-rhxx

<19.3.1-r6
  • L
CVE-2026-13676

<19.3.1-r6
  • L
Resource Exhaustion

<19.3.1-r6
  • L
GHSA-5qhf-9phg-95m2

<19.3.1-r6
  • M
CVE-2025-13465

<19.3.1-r6
  • L
GHSA-fq2j-3j99-rx65

<19.3.1-r6
  • L
GHSA-f2r5-pqh9-r8f8

<19.3.1-r6
  • L
GHSA-6m6c-36f7-fhxh

<19.3.1-r6
  • L
GHSA-4x5r-pxfx-6jf8

<19.3.1-r11
  • L
GHSA-9cv2-cfxc-v4v2

<19.3.1-r6
  • H
Allocation of Resources Without Limits or Throttling

<19.3.1-r6
  • L
GHSA-378v-28hj-76wf

<19.3.1-r6
  • L
GHSA-q8mj-m7cp-5q26

<19.3.1-r6
  • L
CVE-2026-13149

<19.3.1-r6
  • L
CVE-2026-14257

<19.3.1-r6
  • L
GHSA-5prr-v3j2-97mh

<19.3.1-r6
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r6
  • L
GHSA-6g55-p6wh-862q

<19.3.1-r6
  • L
CVE-2026-2739

<19.3.1-r6
  • L
GHSA-x5fp-wj9c-mxmx

<19.3.1-r6
  • L
GHSA-mx8g-39q3-5c79

<19.3.1-r6
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r6
  • L
GHSA-9wx3-p993-35vp

<19.3.1-r6
  • L
Unchecked Input for Loop Condition

<19.3.1-r6
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r6
  • L
GHSA-grv7-fg5c-xmjg

<19.3.1-r6
  • L
GHSA-wfpw-mmfh-qq69

<19.3.1-r6
  • L
GHSA-8678-w3jw-xfc2

<19.3.1-r6
  • L
CVE-2026-56876

<19.3.1-r6
  • L
GHSA-ghhp-3qvg-889p

<19.3.1-r6
  • L
GHSA-52cp-r559-cp3m

<19.3.1-r6
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r6
  • H
CVE-2026-2391

<19.3.1-r6
  • L
GHSA-39j5-w47m-2gmv

<19.3.1-r6
  • L
CVE-2026-45822

<19.3.1-r6
  • L
GHSA-jqff-g426-hqxp

<19.3.1-r6
  • L
GHSA-3jxr-9vmj-r5cp

<19.3.1-r6
  • H
Resource Exhaustion

<19.3.1-r6
  • L
GHSA-jmr9-qjv8-65gv

<19.3.1-r6
  • L
Algorithmic Complexity

<19.3.1-r6
  • L
GHSA-f65p-4m7j-42xc

<19.3.1-r6
  • C
CVE-2026-4800

<19.3.1-r6
  • L
GHSA-mmx7-hfxf-jppx

<19.3.1-r6
  • L
Information Exposure

<19.3.1-r6
  • L
CVE-2026-12143

<19.3.1-r6
  • L
GHSA-6x64-9x62-f2gx

<19.3.1-r6
  • L
CVE-2026-14631

<19.3.1-r6
  • L
Improper Input Validation

<19.3.1-r6
  • L
Server-Side Request Forgery (SSRF)

<19.3.1-r6
  • L
GHSA-f886-m6hf-6m8v

<19.3.1-r6
  • L
GHSA-38c4-r59v-3vqw

<19.3.1-r6
  • L
CVE-2026-6321

<19.3.1-r6
  • L
Allocation of Resources Without Limits or Throttling

<19.3.1-r6
  • L
GHSA-f5vj-f2hx-8m93

<19.3.1-r6
  • L
GHSA-r28c-9q8g-f849

<19.3.1-r6
  • L
GHSA-64mm-vxmg-q3vj

<19.3.1-r6
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r6
  • L
GHSA-8fgc-7cc6-rx7x

<19.3.1-r6
  • L
Algorithmic Complexity

<19.3.1-r6
  • L
GHSA-mh99-v99m-4gvg

<19.3.1-r6
  • L
GHSA-5j98-mcp5-4vw2

<19.3.1-r6
  • M
Arbitrary Code Injection

<19.3.1-r6
  • L
Directory Traversal

<19.3.1-r6
  • L
GHSA-mh29-5h37-fv8m

<19.3.1-r6
  • L
Algorithmic Complexity

<19.3.1-r6
  • L
Arbitrary Code Injection

<19.3.1-r6
  • L
GHSA-wjv4-x9w8-wm3h

<19.3.1-r6
  • L
GHSA-q7cg-457f-vx79

<19.3.1-r6
  • L
Incomplete Blacklist

<19.3.1-r6
  • L
GHSA-m28w-2pqf-7qgj

<19.3.1-r6
  • L
GHSA-6hqm-hm2v-3p2p

<19.3.1-r6
  • L
GHSA-v6h2-p8h4-qcjw

<19.3.1-r6
  • L
GHSA-fxqj-rqcc-2cmp

<19.3.1-r6
  • L
CVE-2026-75975

<19.3.1-r6
  • L
GHSA-55q2-fjhq-7xh7

<19.3.1-r6
  • L
GHSA-2v8p-3f2j-5mp7

<19.3.1-r6
  • L
Allocation of Resources Without Limits or Throttling

<19.3.1-r6
  • L
GHSA-4ww2-rjh2-xpv9

<19.3.1-r6
  • L
GHSA-7fh5-64p2-3v2j

<19.3.1-r6
  • H
Allocation of Resources Without Limits or Throttling

<19.3.1-r6
  • L
GHSA-rf6f-7fwh-wjgh

<19.3.1-r6
  • L
GHSA-w9m9-85wc-3x92

<19.3.1-r10
  • L
Inefficient Regular Expression Complexity

<19.3.1-r6
  • L
GHSA-w7fw-mjwx-w883

<19.3.1-r6
  • L
GHSA-v39h-62p7-jpjc

<19.3.1-r6
  • L
GHSA-qj8w-gfj5-8c6v

<19.3.1-r6
  • L
GHSA-vcc3-ghjq-m6fr

<19.3.1-r6
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<19.3.1-r6
  • L
Resource Exhaustion

<19.3.1-r6
  • L
GHSA-w5hq-g745-h8pq

<19.3.1-r6
  • L
GHSA-96hv-2xvq-fx4p

<19.3.1-r6
  • M
Origin Validation Error

<19.3.1-r6
  • L
GHSA-vp52-pcj8-j9qc

<19.3.1-r6
  • L
GHSA-38r7-794h-5758

<19.3.1-r6
  • L
Directory Traversal

<19.3.1-r6
  • L
Resource Exhaustion

<19.3.1-r6
  • M
Server-Side Request Forgery (SSRF)

<19.3.1-r6
  • H
Inefficient Regular Expression Complexity

<19.3.1-r6
  • H
CVE-2026-2327

<19.3.1-r6
  • L
GHSA-5p4m-2wfm-xmqj

<19.3.1-r6
  • L
GHSA-cj75-f6xr-r4g7

<19.3.1-r6
  • H
Resource Exhaustion

<19.3.1-r6
  • L
CVE-2026-4867

<19.3.1-r6
  • M
CVE-2026-6402

<19.3.1-r6
  • L
GHSA-jqh4-m9w3-8hp9

<19.3.1-r6
  • H
Resource Exhaustion

<19.3.1-r6
  • L
GHSA-fv7c-fp4j-7gwp

<19.3.1-r6
  • L
GHSA-h67p-54hq-rp68

<19.3.1-r6
  • L
CVE-2026-14620

<19.3.1-r6
  • L
GHSA-9jgg-88mc-972h

<19.3.1-r6
  • L
Resource Exhaustion

<19.3.1-r6
  • L
GHSA-r292-9mhp-454m

<19.3.1-r6
  • L
GHSA-68jp-44vc-2x5h

<19.3.1-r6
  • L
Algorithmic Complexity

<19.3.1-r6
  • L
GHSA-8j3g-f24p-4mpw

<19.3.1-r6
  • L
GHSA-968p-4wvh-cqc8

<19.3.1-r6
  • L
CVE-2026-3449

<19.3.1-r6
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r6
  • L
GHSA-2g4f-4pwh-qvx6

<19.3.1-r6
  • L
Uncaught Exception

<19.3.1-r6
  • L
Resource Exhaustion

<19.3.1-r6
  • H
Server-Side Request Forgery (SSRF)

<19.3.1-r6
  • L
GHSA-36jr-mh4h-2g58

<19.3.1-r5
  • L
CRLF Injection

<19.3.1-r4
  • L
GHSA-898c-q2cr-xwhg

<19.3.1-r6
  • L
GHSA-j5f8-grm9-p9fc

<19.3.1-r6
  • H
Uncontrolled Recursion

<19.3.1-r6
  • L
GHSA-w9j2-pvgh-6h63

<19.3.1-r6
  • H
Information Exposure

<19.3.1-r6
  • L
GHSA-5c9x-8gcm-mpgx

<19.3.1-r6
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r6
  • L
GHSA-43fc-jf86-j433

<19.3.1-r6
  • L
GHSA-3p68-rc4w-qgx5

<19.3.1-r6
  • L
GHSA-fvcv-3m26-pcqx

<19.3.1-r6
  • L
HTTP Response Splitting

<19.3.1-r6
  • L
GHSA-pf86-5x62-jrwf

<19.3.1-r6
  • C
Unintended Proxy or Intermediary ('Confused Deputy')

<19.3.1-r6
  • L
GHSA-3g43-6gmg-66jw

<19.3.1-r6
  • L
Improper Encoding or Escaping of Output

<19.3.1-r6
  • M
HTTP Response Splitting

<19.3.1-r6
  • L
Allocation of Resources Without Limits or Throttling

<19.3.1-r4
  • L
GHSA-vf2m-468p-8v99

<19.3.1-r6
  • L
GHSA-pmwg-cvhr-8vh7

<19.3.1-r6
  • L
GHSA-xx6v-rp6x-q39c

<19.3.1-r6
  • L
Allocation of Resources Without Limits or Throttling

<19.3.1-r4
  • L
Permissive Whitelist

<19.3.1-r6
  • L
Resource Exhaustion

<19.3.1-r6
  • L
GHSA-p92q-9vqr-4j8v

<19.3.1-r6
  • L
GHSA-q8qp-cvcw-x6jj

<19.3.1-r4
  • L
Improper Check for Unusual or Exceptional Conditions

<19.3.1-r6
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r6
  • C
Permissive Whitelist

<19.3.1-r6
  • L
Allocation of Resources Without Limits or Throttling

<19.3.1-r6
  • L
GHSA-3w6x-2g7m-8v23

<19.3.1-r4
  • L
GHSA-hfxv-24rg-xrqf

<19.3.1-r6
  • L
GHSA-62hf-57xw-28j9

<19.3.1-r6
  • L
Allocation of Resources Without Limits or Throttling

<19.3.1-r6
  • H
Arbitrary Code Injection

<19.3.1-r6
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r4
  • L
GHSA-35jp-ww65-95wh

<19.3.1-r4
  • L
GHSA-4hjh-wcwx-xvwj

<19.3.1-r4
  • L
GHSA-445q-vr5w-6q77

<19.3.1-r4
  • M
Improper Authentication

<19.3.1-r6
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<19.3.1-r4
  • L
GHSA-777c-7fjr-54vf

<19.3.1-r4
  • L
GHSA-r4q5-vmmm-2653

<19.3.1-r4
  • L
Information Exposure

<19.3.1-r6
  • L
GHSA-6chq-wfr3-2hj9

<19.3.1-r6
  • L
GHSA-xhjh-pmcv-23jw

<19.3.1-r6
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<19.3.1-r4
  • L
GHSA-m7pr-hjqh-92cm

<19.3.1-r6
  • L
GHSA-28wg-ghj8-5hjv

<19.3.1-r1
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<19.3.1-r1
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<19.3.1-r1
  • L
GHSA-2v37-7h3g-55p8

<19.3.1-r1