gitlab-rails-ce-fips-19.2

Direct Vulnerabilities

Known vulnerabilities in the gitlab-rails-ce-fips-19.2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-395f-4hp3-45gv

<19.2.5-r0
  • L
CVE-2026-13311

<19.2.5-r0
  • L
GHSA-36jr-mh4h-2g58

<19.2.4-r4
  • L
CRLF Injection

<19.2.4-r3
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<19.2.4-r3
  • L
GHSA-q8qp-cvcw-x6jj

<19.2.4-r3
  • L
GHSA-3w6x-2g7m-8v23

<19.2.4-r3
  • L
Allocation of Resources Without Limits or Throttling

<19.2.4-r3
  • L
GHSA-445q-vr5w-6q77

<19.2.4-r3
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<19.2.4-r3
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.2.4-r3
  • L
GHSA-35jp-ww65-95wh

<19.2.4-r3
  • L
GHSA-777c-7fjr-54vf

<19.2.4-r3
  • L
XML Injection

<19.2.4-r2
  • L
GHSA-wh4c-j3r5-mjhp

<19.2.4-r2
  • L
GHSA-2v35-w6hq-6mfw

<19.2.4-r2
  • L
XML Injection

<19.2.4-r2
  • L
GHSA-x6wf-f3px-wcqx

<19.2.4-r2
  • L
Uncontrolled Recursion

<19.2.4-r2
  • L
XML Injection

<19.2.4-r2
  • L
XML Injection

<19.2.4-r2
  • L
GHSA-f6ww-3ggp-fr8h

<19.2.4-r2
  • L
GHSA-j759-j44w-7fr8

<19.2.4-r2
  • L
GHSA-2m8v-j782-fhvr

<19.2.4-r1
  • L
Improper Input Validation

<19.2.4-r1
  • L
GHSA-28wg-ghj8-5hjv

<19.2.1-r7
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<19.2.1-r7
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<19.2.1-r7
  • L
GHSA-2v37-7h3g-55p8

<19.2.1-r7
  • L
GHSA-25h7-pfq9-p65f

<19.2.1-r6
  • L
Uncontrolled Recursion

<19.2.1-r6
  • L
Improper Input Validation

<19.2.1-r5
  • L
GHSA-ppp5-5v6c-4jwp

<19.2.1-r5
  • L
GHSA-q67f-28xg-22rw

<19.2.1-r5
  • L
GHSA-65ch-62r8-g69g

<19.2.1-r5
  • L
GHSA-5gfm-wpxj-wjgq

<19.2.1-r5
  • L
Improper Verification of Cryptographic Signature

<19.2.1-r5
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

<19.2.1-r5
  • C
Improper Certificate Validation

<19.2.1-r5
  • L
GHSA-554w-wpv2-vw27

<19.2.1-r5
  • L
CVE-2025-12816

<19.2.1-r5
  • M
Integer Overflow or Wraparound

<19.2.1-r5
  • L
GHSA-5m6q-g25r-mvwx

<19.2.1-r5
  • H
Uncontrolled Recursion

<19.2.1-r5
  • L
GHSA-2328-f5f3-gj25

<19.2.1-r5
  • L
GHSA-83g3-92jg-28cx

<19.2.1-r4
  • L
Directory Traversal

<19.2.1-r4
  • M
Directory Traversal

<19.2.1-r4
  • L
GHSA-34x7-hfp2-rc4v

<19.2.1-r4
  • M
Improper Handling of Unicode Encoding

<19.2.1-r4
  • L
GHSA-qffp-2rhf-9h96

<19.2.1-r4
  • H
Directory Traversal

<19.2.1-r4
  • L
Incorrect Type Conversion or Cast

<19.2.1-r4
  • L
GHSA-vmf3-w455-68vh

<19.2.1-r4
  • L
Interpretation Conflict

<19.2.1-r4
  • L
GHSA-9ppj-qmqm-q256

<19.2.1-r4
  • L
GHSA-w8wr-v893-vjvp

<19.2.1-r4
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

<19.2.1-r4
  • L
Allocation of Resources Without Limits or Throttling

<19.2.1-r4
  • L
Uncaught Exception

<19.2.1-r4
  • L
GHSA-23hp-3jrh-7fpw

<19.2.1-r4
  • M
Directory Traversal

<19.2.1-r4
  • L
GHSA-gvwx-54wh-qm9j

<19.2.1-r4
  • M
Directory Traversal

<19.2.1-r4
  • L
GHSA-8x88-c5mf-7j5w

<19.2.1-r4
  • L
GHSA-r6q2-hw4h-h46w

<19.2.1-r4
  • L
GHSA-8qq5-rm4j-mr97

<19.2.1-r4
  • L
Directory Traversal

<19.2.1-r3
  • L
Link Following

<19.2.1-r3
  • L
GHSA-hc8v-wwc9-vgxm

<19.2.1-r3
  • L
GHSA-qgq7-7hm3-q39j

<19.2.1-r3
  • L
GHSA-22p9-wv53-3rq4

<19.2.1-r2
  • L
GHSA-v245-v573-v5vm

<19.2.1-r2
  • H
Inefficient Regular Expression Complexity

<19.2.1-r2
  • L
Algorithmic Complexity

<19.2.1-r2
  • M
Directory Traversal

<19.2.1-r1
  • L
GHSA-p9ff-h696-f583

<19.2.1-r1
  • M
Directory Traversal

<19.2.1-r1
  • L
External Control of File Name or Path

<19.2.1-r1
  • L
Directory Traversal

<19.2.1-r1
  • L
GHSA-5xrq-8626-4rwp

<19.2.1-r1
  • L
GHSA-fx2h-pf6j-xcff

<19.2.1-r1
  • L
GHSA-v6wh-96g9-6wx3

<19.2.1-r1
  • L
GHSA-v2wj-q39q-566r

<19.2.1-r1
  • H
Incorrect Behavior Order: Validate Before Canonicalize

<19.2.1-r1
  • H
Information Exposure

<19.2.1-r1
  • L
GHSA-4w7w-66w2-5vf9

<19.2.1-r1
  • L
GHSA-xr9x-r78c-5hrm

<19.2.1-r0
  • L
Insecure Default Initialization of Resource

<19.2.1-r0