References https://www.aliyun.com/notice/112888 https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/GitLab-%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E-CVE-2021-22205.md https://nosec.org/m/share/4699.html https://www.pldsec.com/servicedetail.aspx?id=C7397D047187AFDE https://it.ruc.edu.cn/wlaq/461fc0a86df443148d84b5d74ab6437a.htm https://about.gitlab.com/releases/2021/03/17/security-release-gitlab-13-9-4-released/ https://github.com/CsEnox/GitLab-Wiki-RCE https://hackerone.com/reports/1125425 https://gitlab.com/gitlab-org/gitlab/-/issues/324452 https://zone.ci/aliyun/ali_highrisk/11611.html
Related VulnerabilitiesPoCCVE-2026-85706: GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File ReadGitLab CE/EE /api/graphql 未授权访问漏洞(CVE-2026-19478)PoCCVE-2026-19478: GitLab CE/EE - GraphQL @gl_introduced Arbitrary Method InvocationElestio Memos /api/v1/markdown/link:metadata 服务器端请求伪造漏洞(CVE-2025-22952)Stirling-PDF /api/v1/convert/markdown/pdf 服务器端请求伪造漏洞 (CVE-2025-55161)PoCCVE-2021-22175: GitLab CI Lint API - Server-Side Request ForgeryGitLab GitLab CE/EE 权限管理不当漏洞GitLab CE/EE GraphQL 身份验证缺陷漏洞GitLab CE/EE 资源分配控制不当漏洞 可导致拒绝服务gitlab-api-user-enum: GitLab - User Information Disclosure Via Open API(CVE-2025-55161) Stirling-PDF Markdown转PDF功能中sanitizer绕过导致SSRF漏洞PoCCVE-2024-45409: GitLab - SAML Authentication BypassPoCCVE-2025-25291: GitLab - SAML Authentication Bypass