← All credits
daw10
30 vulnerability records and advisories credit this contributor.
CVE-2026-5132
Unbounded zlib decompression in Calls SDP WebSocket messages
CVE-2026-4915
Server panic via outgoing webhook responses
CVE-2026-4858
Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.
CVE-2026-4635
Persistent notification timing attack causing server denial of service
CVE-2026-5163
Missing authorization check in AI message rewrite endpoint allows access to private thread content
CVE-2026-4274
Insufficient authorization in shared channel membership sync grants team-level access instead of channel-level access
CVE-2026-4273
Insufficient token rotation validation in remote cluster invite confirmation
CVE-2026-3117
Instance and webhook GitLab plugin commands were able to be run by non-admin users
CVE-2026-2462
Admin RCE via Malicious Plugin Upload on CI Test Instances
CVE-2026-2457
WebSocket Message Spoofing via Permalink Embed Manipulation