gitlab-rails-ce-fips-19.1

Direct Vulnerabilities

Known vulnerabilities in the gitlab-rails-ce-fips-19.1 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-mp7j-qc5w-4988

<19.1.2-r7
  • L
Improper Handling of Length Parameter Inconsistency

<19.1.2-r7
  • L
GHSA-xv26-6w52-cph6

<19.1.2-r7
  • L
Allocation of Resources Without Limits or Throttling

<19.1.2-r7
  • L
CVE-2026-9277

<19.1.2-r5
  • L
GHSA-w7jw-789q-3m8p

<19.1.2-r5
  • L
GHSA-cpq7-6gpm-g9rc

<19.1.2-r4
  • C
CVE-2025-9287

<19.1.2-r4
  • L
GHSA-v62p-rq8g-8h59

<19.1.2-r3
  • L
CVE-2025-6547

<19.1.2-r3
  • L
CVE-2025-6545

<19.1.2-r3
  • L
GHSA-h7cp-r72f-jxh6

<19.1.2-r3
  • L
Improper Input Validation

<19.1.2-r2
  • C
Improper Encoding or Escaping of Output

<19.1.2-r2
  • L
GHSA-jpcc-p29g-p8mq

<19.1.2-r2
  • L
CVE-2026-42505

<19.1.2-r2
  • L
GHSA-ff52-ph69-cf7x

<19.1.2-r2
  • L
CVE-2026-47262

<19.1.2-r2
  • L
GHSA-crhj-59gh-8x96

<19.1.2-r2
  • L
Directory Traversal

<19.1.2-r2
  • L
GHSA-w5pp-99ch-qj29

<19.1.2-r2
  • L
GHSA-xhf5-7wjv-pqxp

<19.1.2-r2
  • L
GHSA-m7cr-m3pv-hgrp

<19.1.2-r2
  • L
GHSA-95m3-7q98-8xr5

<19.1.1-r4
  • C
CVE-2025-9288

<19.1.1-r4
  • L
Improper Input Validation

<19.1.1-r2
  • L
GHSA-cvxm-645q-p574

<19.1.1-r2
  • L
GHSA-p9ff-h696-f583

<19.1.1-r3
  • L
GHSA-v2wj-q39q-566r

<19.1.1-r3
  • M
Directory Traversal

<19.1.1-r3
  • L
GHSA-rgh6-rfwx-v388

<19.1.1-r2
  • L
CVE-2026-50195

<19.1.1-r2
  • L
GHSA-5xrq-8626-4rwp

<19.1.1-r3
  • L
Symlink Following

<19.1.1-r2
  • H
Incorrect Behavior Order: Validate Before Canonicalize

<19.1.1-r3
  • L
Directory Traversal

<19.1.1-r3
  • C
Directory Traversal

<19.1.1-r2
  • L
GHSA-33vj-92qq-66hc

<19.1.1-r2
  • H
Information Exposure

<19.1.1-r3
  • L
GHSA-4w7w-66w2-5vf9

<19.1.1-r3
  • L
GHSA-84xv-jfrm-h4gm

<19.1.1-r2
  • L
Server-Side Request Forgery (SSRF)

<19.1.1-r1
  • L
GHSA-7mvr-c777-76hp

<19.1.1-r1
  • L
GHSA-968p-4wvh-cqc8

<19.1.1-r1
  • L
GHSA-xhjh-pmcv-23jw

<19.1.1-r1
  • L
GHSA-qffp-2rhf-9h96

<19.1.1-r1
  • L
GHSA-fvcv-3m26-pcqx

<19.1.1-r1
  • L
Allocation of Resources Without Limits or Throttling

<19.1.1-r1
  • L
GHSA-34x7-hfp2-rc4v

<19.1.1-r1
  • H
CVE-2026-2391

<19.1.1-r1
  • L
Inefficient Regular Expression Complexity

<19.1.1-r1
  • L
GHSA-vmf3-w455-68vh

<19.1.1-r1
  • M
Improper Handling of Unicode Encoding

<19.1.1-r1
  • L
Improper Encoding or Escaping of Output

<19.1.1-r1
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.1.1-r1
  • L
GHSA-xjpj-3mr7-gcpf

<19.1.1-r1
  • L
GHSA-xx6v-rp6x-q39c

<19.1.1-r1
  • L
CVE-2024-4068

<19.1.1-r1
  • L
GHSA-f886-m6hf-6m8v

<19.1.1-r1
  • H
Inefficient Regular Expression Complexity

<19.1.1-r1
  • L
GHSA-6rw7-vpxm-498p

<19.1.1-r1
  • H
Use of Uninitialized Resource

<19.1.1-r1
  • M
Cross-site Scripting (XSS)

<19.1.1-r1
  • L
Resource Exhaustion

<19.1.1-r1
  • L
GHSA-c2c7-rcm5-vvqj

<19.1.1-r1
  • L
Uncontrolled Recursion

<19.1.1-r1
  • C
Unintended Proxy or Intermediary ('Confused Deputy')

<19.1.1-r1
  • L
Arbitrary Code Injection

<19.1.1-r1
  • H
Uncontrolled Recursion

<19.1.1-r1
  • L
Allocation of Resources Without Limits or Throttling

<19.1.1-r1
  • L
GHSA-m7pr-hjqh-92cm

<19.1.1-r1
  • M
Improper Authentication

<19.1.1-r1
  • L
GHSA-3mfm-83xf-c92r

<19.1.1-r1
  • L
GHSA-fv7c-fp4j-7gwp

<19.1.1-r1
  • L
GHSA-777c-7fjr-54vf

<19.1.1-r1
  • L
GHSA-3g43-6gmg-66jw

<19.1.1-r1
  • C
CVE-2026-4800

<19.1.1-r1
  • L
GHSA-4x5r-pxfx-6jf8

<19.1.1-r1
  • L
GHSA-q8qp-cvcw-x6jj

<19.1.1-r1
  • L
GHSA-p92q-9vqr-4j8v

<19.1.1-r1
  • L
GHSA-2w6w-674q-4c4q

<19.1.1-r1
  • M
CVE-2025-13465

<19.1.1-r1
  • L
CVE-2026-6321

<19.1.1-r1
  • L
GHSA-r4q5-vmmm-2653

<19.1.1-r1
  • L
GHSA-w7fw-mjwx-w883

<19.1.1-r1
  • L
HTTP Response Splitting

<19.1.1-r1
  • L
GHSA-hmw2-7cc7-3qxx

<19.1.1-r1
  • L
GHSA-43fc-jf86-j433

<19.1.1-r1
  • L
GHSA-83g3-92jg-28cx

<19.1.1-r1
  • M
CVE-2024-4067

<19.1.1-r1
  • L
GHSA-v6h2-p8h4-qcjw

<19.1.1-r1
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.1.1-r1
  • L
GHSA-xxjr-mmjv-4gpg

<19.1.1-r1
  • L
GHSA-f23m-r3pf-42rh

<19.1.1-r1
  • L
GHSA-fjxv-7rqg-78g4

<19.1.1-r1
  • L
GHSA-qj8w-gfj5-8c6v

<19.1.1-r1
  • L
GHSA-9cx6-37pm-9jff

<19.1.1-r1
  • L
Server-Side Request Forgery (SSRF)

<19.1.1-r1
  • H
Resource Exhaustion

<19.1.1-r1
  • L
GHSA-8qq5-rm4j-mr97

<19.1.1-r1
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.1.1-r1
  • L
Resource Exhaustion

<19.1.1-r1
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<19.1.1-r1
  • L
CVE-2025-7339

<19.1.1-r1
  • L
GHSA-5c6j-r48x-rmvq

<19.1.1-r1
  • L
GHSA-37ch-88jc-xwx2

<19.1.1-r1
  • L
GHSA-23c5-xmqv-rm74

<19.1.1-r1
  • L
GHSA-737v-mqg7-c878

<19.1.1-r1
  • L
GHSA-vj76-c3g6-qr5v

<19.1.1-r1
  • H
Information Exposure

<19.1.1-r1
  • M
Directory Traversal

<19.1.1-r1
  • L
GHSA-h67p-54hq-rp68

<19.1.1-r1
  • L
Allocation of Resources Without Limits or Throttling

<19.1.1-r1
  • L
GHSA-2g4f-4pwh-qvx6

<19.1.1-r1
  • L
GHSA-qx2v-qp2m-jg93

<19.1.1-r1
  • L
GHSA-q8mj-m7cp-5q26

<19.1.1-r1
  • H
Directory Traversal

<19.1.1-r1
  • L
GHSA-4hjh-wcwx-xvwj

<19.1.1-r1
  • L
Interpretation Conflict

<19.1.1-r1
  • L
GHSA-wf6x-7x77-mvgw

<19.1.1-r1
  • L
Resource Exhaustion

<19.1.1-r1
  • L
GHSA-62hf-57xw-28j9

<19.1.1-r1
  • L
Directory Traversal

<19.1.1-r1
  • L
Arbitrary Code Injection

<19.1.1-r1
  • L
GHSA-8cj5-5rvv-wf4v

<19.1.1-r1
  • L
GHSA-vf2m-468p-8v99

<19.1.1-r1
  • L
Arbitrary Code Injection

<19.1.1-r1
  • L
GHSA-38r7-794h-5758

<19.1.1-r1
  • L
Improper Check for Unusual or Exceptional Conditions

<19.1.1-r1
  • L
Server-Side Request Forgery (SSRF)

<19.1.1-r1
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.1.1-r1
  • L
GHSA-hfxv-24rg-xrqf

<19.1.1-r1
  • H
Server-Side Request Forgery (SSRF)

<19.1.1-r1
  • L
GHSA-7fh5-64p2-3v2j

<19.1.1-r1
  • L
Algorithmic Complexity

<19.1.1-r1
  • L
GHSA-8fgc-7cc6-rx7x

<19.1.1-r1
  • L
CVE-2026-12143

<19.1.1-r1
  • L
GHSA-pf86-5x62-jrwf

<19.1.1-r1
  • C
Permissive Whitelist

<19.1.1-r1
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.1.1-r1
  • M
CVE-2026-2950

<19.1.1-r1
  • L
Arbitrary Code Injection

<19.1.1-r1
  • L
GHSA-6chq-wfr3-2hj9

<19.1.1-r1
  • L
GHSA-w5hq-g745-h8pq

<19.1.1-r1
  • L
GHSA-grv7-fg5c-xmjg

<19.1.1-r1
  • L
GHSA-q3j6-qgpj-74h6

<19.1.1-r1
  • L
GHSA-pmwg-cvhr-8vh7

<19.1.1-r1
  • L
GHSA-7r86-cg39-jmmj

<19.1.1-r1
  • L
GHSA-3v7f-55p6-f55p

<19.1.1-r1
  • L
GHSA-w9j2-pvgh-6h63

<19.1.1-r1
  • L
CVE-2025-15284

<19.1.1-r1
  • L
GHSA-35jp-ww65-95wh

<19.1.1-r1
  • L
Directory Traversal

<19.1.1-r1
  • L
Information Exposure

<19.1.1-r1
  • L
Inefficient Regular Expression Complexity

<19.1.1-r1
  • L
GHSA-pjwm-pj3p-43mv

<19.1.1-r1
  • L
GHSA-3w6x-2g7m-8v23

<19.1.1-r1
  • L
Inefficient Regular Expression Complexity

<19.1.1-r1
  • L
CVE-2026-4867

<19.1.1-r1
  • H
Arbitrary Code Injection

<19.1.1-r1
  • L
Permissive Whitelist

<19.1.1-r1
  • L
GHSA-96hv-2xvq-fx4p

<19.1.1-r1
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.1.1-r1
  • M
Improper Verification of Cryptographic Signature

<19.1.1-r1
  • L
GHSA-442j-39wm-28r2

<19.1.1-r1
  • L
Algorithmic Complexity

<19.1.1-r1
  • L
Cross-site Scripting (XSS)

<19.1.1-r1
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.1.1-r1
  • L
GHSA-58qx-3vcg-4xpx

<19.1.1-r1
  • L
GHSA-445q-vr5w-6q77

<19.1.1-r1
  • L
GHSA-7rx3-28cr-v5wh

<19.1.1-r1
  • L
GHSA-q7cg-457f-vx79

<19.1.1-r1
  • L
Directory Traversal

<19.1.1-r1
  • L
CVE-2026-8723

<19.1.1-r1
  • L
OS Command Injection

<19.1.1-r1
  • H
Cross-site Scripting (XSS)

<19.1.1-r1
  • L
Allocation of Resources Without Limits or Throttling

<19.1.1-r1
  • L
CRLF Injection

<19.1.1-r1
  • L
GHSA-mh29-5h37-fv8m

<19.1.1-r1
  • L
GHSA-5j98-mcp5-4vw2

<19.1.1-r1
  • L
GHSA-76c9-3jph-rj3q

<19.1.1-r1
  • L
GHSA-j5f8-grm9-p9fc

<19.1.1-r1
  • M
Directory Traversal

<19.1.1-r1
  • L
GHSA-r5fr-rjxr-66jc

<19.1.1-r1
  • L
GHSA-v39h-62p7-jpjc

<19.1.1-r1
  • L
Uncaught Exception

<19.1.1-r1
  • L
GHSA-9ppj-qmqm-q256

<19.1.1-r1
  • L
GHSA-898c-q2cr-xwhg

<19.1.1-r1
  • L
GHSA-3p68-rc4w-qgx5

<19.1.1-r1
  • L
GHSA-r6q2-hw4h-h46w

<19.1.1-r1
  • L
GHSA-952p-6rrq-rcjv

<19.1.1-r1
  • L
Improper Check for Unusual or Exceptional Conditions

<19.1.1-r1
  • L
GHSA-67mh-4wv8-2f99

<19.1.1-r1
  • L
GHSA-48c2-rrv3-qjmp

<19.1.1-r1
  • L
CVE-2026-6322

<19.1.1-r1
  • H
Resource Exhaustion

<19.1.1-r1
  • L
Directory Traversal

<19.1.1-r1
  • M
HTTP Response Splitting

<19.1.1-r1
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<19.1.1-r1
  • L
GHSA-xhpv-hc6g-r9c6

<19.1.1-r1
  • L
GHSA-5c9x-8gcm-mpgx

<19.1.1-r1
  • H
Out-of-bounds Write

<19.1.1-r1
  • M
Arbitrary Code Injection

<19.1.1-r1
  • L
GHSA-3ppc-4f35-3m26

<19.1.1-r1
  • L
CVE-2025-7783

<19.1.1-r1
  • L
Inefficient Regular Expression Complexity

<19.1.1-r1
  • L
GHSA-2qvq-rjwj-gvw9

<19.1.1-r1
  • M
Directory Traversal

<19.1.1-r1