← All credits
Thanks [joaxcar](https://hackerone.com/joaxcar) for reporting this vulnerability through our HackerOne bug bounty program
104 vulnerability records and advisories credit this contributor.
CVE-2026-84739
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
CVE-2026-88765
Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab
CVE-2026-89078
Double Free in GitLab
CVE-2026-93577
Integer Overflow or Wraparound in GitLab
CVE-2026-1168
Allocation of Resources Without Limits or Throttling in GitLab
CVE-2025-13761
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
CVE-2026-10712
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
CVE-2026-6073
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
CVE-2026-5816
Improper Resolution of Path Equivalence in GitLab
CVE-2026-5262
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab