gitlab-rails-ce-fips-19.3

Direct Vulnerabilities

Known vulnerabilities in the gitlab-rails-ce-fips-19.3 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-2wm5-q62r-hmrv

<19.3.2-r1
  • L
GHSA-7jxh-36q5-gcqv

<19.3.2-r1
  • L
Resource Exhaustion

<19.3.2-r1
  • L
Inefficient Regular Expression Complexity

<19.3.2-r1
  • L
GHSA-2v4p-qf9q-27wj

<19.3.1-r7
  • L
Directory Traversal

<19.3.1-r7
  • L
GHSA-82fw-gwwq-j7x9

<19.3.1-r7
  • L
Improper Validation of Array Index

<19.3.1-r7
  • L
Directory Traversal

<19.3.1-r6
  • L
CVE-2024-47764

<19.3.1-r6
  • L
GHSA-4x5r-pxfx-6jf8

<19.3.1-r6
  • L
GHSA-pxg6-pf52-xh8x

<19.3.1-r6
  • L
GHSA-w9m9-85wc-3x92

<19.3.1-r5
  • M
Improper Resource Shutdown or Release

<19.3.1-r5
  • L
CVE-2025-57352

<19.3.1-r4
  • L
GHSA-rx8g-88g5-qh64

<19.3.1-r4
  • H
Allocation of Resources Without Limits or Throttling

<19.3.1-r3
  • L
GHSA-3v7f-55p6-f55p

<19.3.1-r3
  • L
CVE-2025-15284

<19.3.1-r3
  • L
XML Injection

<19.3.1-r3
  • L
GHSA-4v9v-hfq4-rm2v

<19.3.1-r3
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<19.3.1-r3
  • L
GHSA-952p-6rrq-rcjv

<19.3.1-r3
  • L
Arbitrary Code Injection

<19.3.1-r3
  • L
GHSA-vcc3-ghjq-m6fr

<19.3.1-r3
  • L
GHSA-x2f5-4prf-w687

<19.3.1-r3
  • L
GHSA-ghcm-xqfw-q4vr

<19.3.1-r3
  • L
XML Injection

<19.3.1-r3
  • M
CVE-2026-6402

<19.3.1-r3
  • L
GHSA-37ch-88jc-xwx2

<19.3.1-r3
  • L
XML Injection

<19.3.1-r3
  • L
GHSA-v2hh-gcrm-f6hx

<19.3.1-r3
  • L
GHSA-pmv8-rq9r-6j72

<19.3.1-r3
  • L
GHSA-5c6j-r48x-rmvq

<19.3.1-r3
  • H
Resource Exhaustion

<19.3.1-r3
  • L
XML Injection

<19.3.1-r3
  • L
GHSA-j759-j44w-7fr8

<19.3.1-r3
  • L
GHSA-c2c7-rcm5-vvqj

<19.3.1-r3
  • L
Directory Traversal

<19.3.1-r3
  • L
GHSA-r292-9mhp-454m

<19.3.1-r3
  • L
GHSA-6g55-p6wh-862q

<19.3.1-r3
  • L
GHSA-3w6x-2g7m-8v23

<19.3.1-r3
  • L
CVE-2026-13149

<19.3.1-r3
  • M
Improper Authentication

<19.3.1-r3
  • L
GHSA-5p4m-2wfm-xmqj

<19.3.1-r3
  • L
Improper Encoding or Escaping of Output

<19.3.1-r3
  • L
GHSA-wf5p-g6vw-rhxx

<19.3.1-r3
  • M
CVE-2026-9595

<19.3.1-r3
  • L
Cross-site Scripting (XSS)

<19.3.1-r3
  • L
GHSA-rf6f-7fwh-wjgh

<19.3.1-r3
  • M
HTTP Response Splitting

<19.3.1-r3
  • L
GHSA-f5vj-f2hx-8m93

<19.3.1-r3
  • L
GHSA-3ppc-4f35-3m26

<19.3.1-r3
  • L
Information Exposure

<19.3.1-r3
  • L
Allocation of Resources Without Limits or Throttling

<19.3.1-r3
  • L
Information Exposure

<19.3.1-r3
  • L
Cross-site Scripting (XSS)

<19.3.1-r3
  • L
GHSA-43fc-jf86-j433

<19.3.1-r3
  • L
Server-Side Request Forgery (SSRF)

<19.3.1-r3
  • L
GHSA-3jxr-9vmj-r5cp

<19.3.1-r3
  • L
GHSA-5qhf-9phg-95m2

<19.3.1-r3
  • L
GHSA-pmwg-cvhr-8vh7

<19.3.1-r3
  • H
Arbitrary Code Injection

<19.3.1-r3
  • L
GHSA-hmw2-7cc7-3qxx

<19.3.1-r3
  • H
Resource Exhaustion

<19.3.1-r3
  • L
GHSA-7p8r-x3mc-p8w7

<19.3.1-r3
  • H
Resource Exhaustion

<19.3.1-r3
  • L
GHSA-jqh4-m9w3-8hp9

<19.3.1-r3
  • M
Arbitrary Code Injection

<19.3.1-r3
  • L
Improper Input Validation

<19.3.1-r3
  • H
Resource Exhaustion

<19.3.1-r3
  • L
Inefficient Regular Expression Complexity

<19.3.1-r3
  • L
Algorithmic Complexity

<19.3.1-r3
  • L
HTTP Response Splitting

<19.3.1-r3
  • L
GHSA-5j98-mcp5-4vw2

<19.3.1-r3
  • L
Allocation of Resources Without Limits or Throttling

<19.3.1-r3
  • L
GHSA-mh29-5h37-fv8m

<19.3.1-r3
  • L
Heap-based Buffer Overflow

<19.3.1-r3
  • L
CVE-2026-6321

<19.3.1-r3
  • M
Resource Exhaustion

<19.3.1-r3
  • L
GHSA-48rx-c7pg-q66r

<19.3.1-r3
  • L
GHSA-xvcm-6775-5m9r

<19.3.1-r3
  • L
GHSA-7r86-cg39-jmmj

<19.3.1-r3
  • L
Uncaught Exception

<19.3.1-r3
  • M
Exposed Dangerous Method or Function

<19.3.1-r3
  • H
Server-Side Request Forgery (SSRF)

<19.3.1-r3
  • L
GHSA-xcj9-5m2h-648r

<19.3.1-r3
  • L
GHSA-v39h-62p7-jpjc

<19.3.1-r3
  • H
Directory Traversal

<19.3.1-r3
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r3
  • L
GHSA-8j3g-f24p-4mpw

<19.3.1-r3
  • L
GHSA-w9j2-pvgh-6h63

<19.3.1-r3
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r3
  • L
GHSA-vf2m-468p-8v99

<19.3.1-r3
  • L
GHSA-grv7-fg5c-xmjg

<19.3.1-r3
  • L
CVE-2026-14631

<19.3.1-r3
  • L
GHSA-p92q-9vqr-4j8v

<19.3.1-r3
  • M
Server-Side Request Forgery (SSRF)

<19.3.1-r3
  • H
Allocation of Resources Without Limits or Throttling

<19.3.1-r3
  • L
GHSA-898c-q2cr-xwhg

<19.3.1-r3
  • L
GHSA-8whx-365g-h9vv

<19.3.1-r3
  • L
CVE-2025-7339

<19.3.1-r3
  • L
GHSA-fxqj-rqcc-2cmp

<19.3.1-r3
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r3
  • C
Permissive Whitelist

<19.3.1-r3
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r3
  • L
GHSA-38c4-r59v-3vqw

<19.3.1-r3
  • L
GHSA-jr5f-v2jv-69x6

<19.3.1-r3
  • L
GHSA-mwf2-3pr3-8698

<19.3.1-r3
  • L
CVE-2026-12590

<19.3.1-r3
  • L
GHSA-f4gw-2p7v-4548

<19.3.1-r3
  • L
GHSA-v6h2-p8h4-qcjw

<19.3.1-r3
  • L
GHSA-f6ww-3ggp-fr8h

<19.3.1-r3
  • L
GHSA-fqj3-h9pc-443h

<19.3.1-r3
  • M
Cross-site Request Forgery (CSRF)

<19.3.1-r3
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r3
  • L
GHSA-x6wf-f3px-wcqx

<19.3.1-r3
  • L
Resource Exhaustion

<19.3.1-r3
  • L
GHSA-j5f8-grm9-p9fc

<19.3.1-r3
  • L
GHSA-qj8w-gfj5-8c6v

<19.3.1-r3
  • L
CVE-2026-14620

<19.3.1-r3
  • L
GHSA-3rrr-jr9j-h3q3

<19.3.1-r3
  • L
CVE-2026-13311

<19.3.1-r3
  • M
Directory Traversal

<19.3.1-r3
  • L
GHSA-87f9-hvmw-gh4p

<19.3.1-r3
  • L
CVE-2026-45822

<19.3.1-r3
  • L
GHSA-mh99-v99m-4gvg

<19.3.1-r3
  • L
Resource Exhaustion

<19.3.1-r3
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r3
  • L
GHSA-v422-hmwv-36x6

<19.3.1-r3
  • L
GHSA-xhjh-pmcv-23jw

<19.3.1-r3
  • L
GHSA-2m8v-j782-fhvr

<19.3.1-r3
  • L
GHSA-2g4f-4pwh-qvx6

<19.3.1-r3
  • L
CVE-2026-3449

<19.3.1-r3
  • L
GHSA-378v-28hj-76wf

<19.3.1-r3
  • L
GHSA-3g43-6gmg-66jw

<19.3.1-r3
  • L
GHSA-62hf-57xw-28j9

<19.3.1-r3
  • L
CVE-2026-14257

<19.3.1-r3
  • H
Inefficient Regular Expression Complexity

<19.3.1-r3
  • L
GHSA-pjwm-pj3p-43mv

<19.3.1-r3
  • L
GHSA-42h9-826w-cgv3

<19.3.1-r3
  • L
GHSA-m7pr-hjqh-92cm

<19.3.1-r3
  • L
CVE-2026-6322

<19.3.1-r3
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

<19.3.1-r3
  • L
GHSA-79cf-xcqc-c78w

<19.3.1-r3
  • L
GHSA-6m6c-36f7-fhxh

<19.3.1-r3
  • L
Unchecked Input for Loop Condition

<19.3.1-r3
  • L
Improper Check for Unusual or Exceptional Conditions

<19.3.1-r3
  • L
GHSA-445q-vr5w-6q77

<19.3.1-r3
  • H
Arbitrary Code Injection

<19.3.1-r3
  • L
GHSA-96hv-2xvq-fx4p

<19.3.1-r3
  • H
Allocation of Resources Without Limits or Throttling

<19.3.1-r3
  • L
GHSA-9wjq-cp2p-hrgf

<19.3.1-r3
  • L
Resource Exhaustion

<19.3.1-r3
  • L
GHSA-hfxv-24rg-xrqf

<19.3.1-r3
  • L
GHSA-6v5v-wf23-fmfq

<19.3.1-r3
  • L
GHSA-395f-4hp3-45gv

<19.3.1-r3
  • L
GHSA-4ww2-rjh2-xpv9

<19.3.1-r3
  • L
GHSA-qx2v-qp2m-jg93

<19.3.1-r3
  • H
Resource Exhaustion

<19.3.1-r3
  • L
Resource Exhaustion

<19.3.1-r3
  • L
GHSA-mmx7-hfxf-jppx

<19.3.1-r3
  • L
GHSA-mx8g-39q3-5c79

<19.3.1-r3
  • L
GHSA-f886-m6hf-6m8v

<19.3.1-r3
  • L
Uncontrolled Recursion

<19.3.1-r3
  • L
GHSA-fvcv-3m26-pcqx

<19.3.1-r3
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r3
  • L
GHSA-w7fw-mjwx-w883

<19.3.1-r3
  • L
GHSA-777c-7fjr-54vf

<19.3.1-r3
  • L
GHSA-xx6v-rp6x-q39c

<19.3.1-r3
  • L
GHSA-6hqm-hm2v-3p2p

<19.3.1-r3
  • L
Arbitrary Code Injection

<19.3.1-r3
  • L
CVE-2026-41149

<19.3.1-r3
  • H
CVE-2026-2327

<19.3.1-r3
  • L
OS Command Injection

<19.3.1-r3
  • L
GHSA-52cp-r559-cp3m

<19.3.1-r3
  • L
GHSA-v56q-mh7h-f735

<19.3.1-r3
  • L
GHSA-3p68-rc4w-qgx5

<19.3.1-r3
  • L
Algorithmic Complexity

<19.3.1-r3
  • L
Cross-site Scripting (XSS)

<19.3.1-r3
  • L
GHSA-r28c-9q8g-f849

<19.3.1-r3
  • L
Resource Exhaustion

<19.3.1-r3
  • L
CVE-2026-13676

<19.3.1-r3
  • L
GHSA-vpq2-c234-7xj6

<19.3.1-r3
  • L
GHSA-rgw5-rvv9-x895

<19.3.1-r3
  • L
GHSA-m28w-2pqf-7qgj

<19.3.1-r3
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<19.3.1-r3
  • L
GHSA-pf86-5x62-jrwf

<19.3.1-r3
  • L
GHSA-q8qp-cvcw-x6jj

<19.3.1-r3
  • L
GHSA-2x63-gw47-w4mm

<19.3.1-r3
  • L
CVE-2026-18446

<19.3.1-r3
  • L
GHSA-f2r5-pqh9-r8f8

<19.3.1-r3
  • L
GHSA-jxxr-4gwj-5jf2

<19.3.1-r3
  • L
GHSA-ghhp-3qvg-889p

<19.3.1-r3
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r3
  • C
Directory Traversal

<19.3.1-r3
  • L
GHSA-h67p-54hq-rp68

<19.3.1-r3
  • L
GHSA-39j5-w47m-2gmv

<19.3.1-r3
  • L
GHSA-rhh3-jpg6-66xh

<19.3.1-r3
  • L
GHSA-fq2j-3j99-rx65

<19.3.1-r3
  • L
GHSA-35jp-ww65-95wh

<19.3.1-r3
  • C
Unintended Proxy or Intermediary ('Confused Deputy')

<19.3.1-r3
  • L
GHSA-c4c3-pg64-4m4v

<19.3.1-r3
  • L
Inefficient Regular Expression Complexity

<19.3.1-r3
  • L
Resource Exhaustion

<19.3.1-r3
  • L
GHSA-55q2-fjhq-7xh7

<19.3.1-r3
  • L
CVE-2026-2739

<19.3.1-r3
  • L
Permissive Whitelist

<19.3.1-r3
  • H
Uncontrolled Recursion

<19.3.1-r3
  • L
Improper Input Validation

<19.3.1-r3
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<19.3.1-r3
  • L
CVE-2026-4867

<19.3.1-r3
  • L
CRLF Injection

<19.3.1-r3
  • L
GHSA-q3j6-qgpj-74h6

<19.3.1-r3
  • L
Algorithmic Complexity

<19.3.1-r3
  • L
GHSA-ph9p-34f9-6g65

<19.3.1-r3
  • L
GHSA-fv7c-fp4j-7gwp

<19.3.1-r3
  • L
GHSA-2v35-w6hq-6mfw

<19.3.1-r3
  • L
GHSA-5c9x-8gcm-mpgx

<19.3.1-r3
  • L
GHSA-7fh5-64p2-3v2j

<19.3.1-r3
  • H
Permissive Whitelist

<19.3.1-r3
  • L
GHSA-33ph-fccm-39pj

<19.3.1-r3
  • L
CVE-2026-8723

<19.3.1-r3
  • L
GHSA-qjx8-664m-686j

<19.3.1-r3
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r3
  • L
Inefficient Regular Expression Complexity

<19.3.1-r3
  • L
GHSA-6x64-9x62-f2gx

<19.3.1-r3
  • L
CVE-2024-4068

<19.3.1-r3
  • L
Integer Overflow or Wraparound

<19.3.1-r3
  • L
GHSA-64mm-vxmg-q3vj

<19.3.1-r3
  • L
GHSA-4c8g-83qw-93j6

<19.3.1-r3
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r3
  • L
GHSA-76c9-3jph-rj3q

<19.3.1-r3
  • L
CVE-2026-12143

<19.3.1-r3
  • L
GHSA-wh4c-j3r5-mjhp

<19.3.1-r3
  • L
Allocation of Resources Without Limits or Throttling

<19.3.1-r3
  • L
GHSA-cj75-f6xr-r4g7

<19.3.1-r3
  • L
GHSA-23c5-xmqv-rm74

<19.3.1-r3
  • M
Origin Validation Error

<19.3.1-r3
  • H
CVE-2026-2391

<19.3.1-r3
  • L
GHSA-9jgg-88mc-972h

<19.3.1-r3
  • L
CVE-2026-16221

<19.3.1-r3
  • L
GHSA-6rw7-vpxm-498p

<19.3.1-r3
  • L
GHSA-2v8p-3f2j-5mp7

<19.3.1-r3
  • L
GHSA-6chq-wfr3-2hj9

<19.3.1-r3
  • H
Information Exposure

<19.3.1-r3
  • M
CVE-2024-4067

<19.3.1-r3
  • L
GHSA-q8mj-m7cp-5q26

<19.3.1-r3
  • L
Allocation of Resources Without Limits or Throttling

<19.3.1-r3
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<19.3.1-r3
  • L
Incomplete Blacklist

<19.3.1-r3
  • L
GHSA-36jr-mh4h-2g58

<19.3.1-r3
  • M
Arbitrary Code Injection

<19.3.1-r3
  • L
GHSA-9wx3-p993-35vp

<19.3.1-r3
  • L
GHSA-7q8q-rj6j-mhjq

<19.3.1-r3
  • L
Algorithmic Complexity

<19.3.1-r3