CVE-2020-6833: GitLab

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.

Affected products

  • GitLab GitLab: from 11.3.0, before 12.5.9 (fixed in 12.5.9); from 12.6.0, before 12.6.6 (fixed in 12.6.6); from 12.7.2, before 12.7.4 (fixed in 12.7.4)

Published 2020-02-05. Last modified 2026-06-17.