CVE-2023-3441: GitLab

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.

Affected products

  • GitLab GitLab: from 8.0.0, before 16.4.0 (fixed in 16.4.0)

Published 2024-10-01. Last modified 2026-06-17.