<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 09:31:29 +0000</lastBuildDate>
    <item>
      <title>BIT-gitlab-2023-3906 — Improper Validation of Specified Type of Input in GitLab</title>
      <link>https://cve.radiocsirt.org/vuln/bit-gitlab-2023-3906</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-gitlab-2023-3906</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0792 — De multiples vulnérabilités ont été découvertes dans GitLab. Certaines
d'entre elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0792</link>
      <description>certfr-2023-avi-0792</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0792</guid>
    </item>
    <item>
      <title>EUVD-2026-352386</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352386</link>
      <description>EUVD-2026-352386</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352386</guid>
    </item>
    <item>
      <title>fkie_cve-2023-3906</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3906</link>
      <description>&lt;p&gt;An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-3906</guid>
    </item>
    <item>
      <title>GHSA-x2v6-6q9m-6qx9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x2v6-6q9m-6qx9</link>
      <description>&lt;p&gt;An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x2v6-6q9m-6qx9</guid>
    </item>
    <item>
      <title>gsd-2023-3906</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-3906</link>
      <description>gsd-2023-3906</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-3906</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2520 — GitLab: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2520</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um beliebigen Programmcode mit Rechten des Benutzers auszuführen, Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen oder Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um beliebigen Programmcode mit Rechten des Benutzers auszuführen, Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen oder Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2520</guid>
    </item>
  </channel>
</rss>
