<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — GitLab</title><description>Vulnerabilities in GitLab Community and Enterprise Edition — the DevOps platform that, when compromised, can expose an organization&apos;s entire source code history and CI/CD pipeline secrets. Combined article + CVE feed for the GitLab beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2021-22175 — GitLab Server-Side Request Forgery (SSRF) Vulnerability</title><link>https://0daynews.com/cve/cve-2021-22175/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-22175/</guid><description>GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>GitLab</category><category>medium</category><category>cve</category></item><item><title>CVE-2021-22205 — GitLab CE/EE ExifTool Remote Code Execution</title><link>https://0daynews.com/cve/cve-2021-22205/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-22205/</guid><description>An improper-validation vulnerability in GitLab Community Edition and Enterprise Edition allows an unauthenticated attacker to achieve remote code execution by uploading a crafted image file processed through a vulnerable ExifTool image-metadata parser.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>GitLab</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-39935 — GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability</title><link>https://0daynews.com/cve/cve-2021-39935/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-39935/</guid><description>GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API. </description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>GitLab</category><category>medium</category><category>cve</category></item><item><title>CVE-2023-7028 — GitLab Community and Enterprise Editions Improper Access Control Vulnerability</title><link>https://0daynews.com/cve/cve-2023-7028/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-7028/</guid><description>GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>GitLab</category><category>critical</category><category>cve</category></item><item><title>GitLab RCE PoC Published: No Admin Rights Required</title><link>https://0daynews.com/articles/2026-07-25-gitlab-18-11-3-rce-poc-published/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-25-gitlab-18-11-3-rce-poc-published/</guid><description>A working RCE exploit for self-managed GitLab 18.11.3 is now public. Any authenticated user can execute server commands as git — no admin rights needed.</description><pubDate>Sat, 25 Jul 2026 10:00:00 GMT</pubDate><category>GitLab</category><category>article</category></item><item><title>GitLab&apos;s ExifTool RCE Sat Unrecognized for Months</title><link>https://0daynews.com/articles/2026-07-06-gitlab-exiftool-rce-cve-2021-22205/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-06-gitlab-exiftool-rce-cve-2021-22205/</guid><description>CVE-2021-22205 was quietly fixed in April 2021 — but its full unauthenticated remote-code-execution severity wasn&apos;t widely understood until late 2021, by which point mass exploitation had already begun.</description><pubDate>Mon, 06 Jul 2026 13:00:00 GMT</pubDate><category>GitLab</category><category>article</category></item></channel></rss>