https://handbook.gitlab.com/handbook/values/
GitLab Values | The GitLab Handbook
Learn more about how we live our values at GitLab
gitlab valueshandbook
https://advisories.gitlab.com/pypi/pypdf/GHSA-jj6c-8h6c-hppx/
pypdf has long runtimes for wrong size values in cross-reference and object streams | GitLab...
GHSA-jj6c-8h6c-hppx pypdf has long runtimes for wrong size values in cross-reference and object streams: An attacker who uses this vulnerability can craft a...
https://advisories.gitlab.com/npm/undici/CVE-2025-22150/
Use of Insufficiently Random Values in undici | GitLab Advisory Database (GLAD)
CVE-2025-22150 Use of Insufficiently Random Values in undici: Undici fetch() uses Math.random() to choose the boundary for a multipart/form-data request. It is...
userandomvalues
https://docs.gitlab.com/ja-jp/user/application_security/dast/browser/checks/829.2/
Invalid Sub-Resource Integrity values detected | GitLab Docs
GitLab product documentation.
integrity valuesinvalidsubresourcedetected
https://advisories.gitlab.com/golang/github.com/mattermost/mattermost/server/v8/CVE-2024-41926/
Mattermost allows remote actor to set arbitrary RemoteId values for synced users | GitLab Advisory...
https://advisories.gitlab.com/composer/admidio/admidio/CVE-2026-41659/
Admidio Leaks Hidden Profile Field Values via Blind Search Oracle in Member Assignment | GitLab...
CVE-2026-41659 Admidio Leaks Hidden Profile Field Values via Blind Search Oracle in Member Assignment: The member assignment DataTables endpoint...
https://advisories.gitlab.com/gem/prosemirror_to_html/CVE-2025-64501/
Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values | GitLab Advisory...
CVE-2025-64501 Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values: The prosemirror_to_html gem is vulnerable to Cross-Site...
cross site scripting
https://advisories.gitlab.com/golang/github.com/greenpau/caddy-security/CVE-2024-21495/
Use of Insufficiently Random Values | GitLab Advisory Database (GLAD)
CVE-2024-21495 Use of Insufficiently Random Values: Versions of the package github.com/greenpau/caddy-security before 1.0.42 is vulnerable to Insecure...
userandomvaluesgitlabadvisory
https://advisories.gitlab.com/maven/org.apache.zookeeper/zookeeper/CVE-2026-24308/
Apache ZooKeeper has improper handling of configuration values | GitLab Advisory Database (GLAD)
CVE-2026-24308 Apache ZooKeeper has improper handling of configuration values: Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5...
apache zookeeper
https://about.gitlab.com/blog/pyb-all-remote-mark-frein/
How being all-remote helps us practice our values at GitLab
GitLab CEO Sid Sijbrandij and Mark Frein of InVision talk about why all-remote is the future, and moving beyond 'But how do you know they're working?'
all remoteour valueshelps
https://advisories.gitlab.com/cargo/cranelift-codegen/CVE-2022-31169/
Cranelift vulnerable to miscompilation of constant values in division on AArch64 | GitLab Advisory...
CVE-2022-31169 Cranelift vulnerable to miscompilation of constant values in division on AArch64: There was a bug in Wasmtime's code generator, Cranelift, for...
https://advisories.gitlab.com/pypi/ckan/CVE-2023-22746/
Use of Insufficiently Random Values | GitLab Advisory Database (GLAD)
CVE-2023-22746 Use of Insufficiently Random Values: CKAN is an open-source DMS (data management system) for powering data hubs and data portals. When creating...
userandomvaluesgitlabadvisory
https://advisories.gitlab.com/conan/c-ares/CVE-2023-31124/
Use of Insufficiently Random Values | GitLab Advisory Database (GLAD)
CVE-2023-31124 Use of Insufficiently Random Values: c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build...
userandomvaluesgitlabadvisory
https://advisories.gitlab.com/pypi/pypdf/CVE-2026-22690/
pypdf has possible long runtimes for missing /Root object with large /Size values | GitLab Advisory...
CVE-2026-22690 pypdf has possible long runtimes for missing /Root object with large /Size values: An attacker who exploits this vulnerability can craft a PDF...
https://advisories.gitlab.com/gem/icalendar/CVE-2026-33635/
iCalendar has ICS injection via unsanitized URI property values | GitLab Advisory Database (GLAD)
CVE-2026-33635 iCalendar has ICS injection via unsanitized URI property values: .ics serialization does not properly sanitize URI property values, enabling ICS...
https://advisories.gitlab.com/swift/leaf-kit/CVE-2026-28499/
LeafKit's HTML escaping may be skipped for Collection values, enabling XSS | GitLab Advisory...
CVE-2026-28499 LeafKit's HTML escaping may be skipped for Collection values, enabling XSS: LeafKit HTML-escaping is not working correctly when a template...
https://advisories.gitlab.com/pypi/pypdf/CVE-2026-31826/
pypdf: manipulated stream length values can exhaust RAM | GitLab Advisory Database (GLAD)
CVE-2026-31826 pypdf: manipulated stream length values can exhaust RAM: An attacker who uses this vulnerability can craft a PDF which leads to large memory...
https://advisories.gitlab.com/golang/golang.org/x/crypto/CVE-2019-11840/
Use of Insufficiently Random Values | GitLab Advisory Database (GLAD)
CVE-2019-11840 Use of Insufficiently Random Values: An issue was discovered in supplementary Go cryptography libraries, aka golang-googlecode-go-crypto, before...
userandomvaluesgitlabadvisory
https://advisories.gitlab.com/npm/@dfinity/auth-client/CVE-2024-1631/
Use of Insufficiently Random Values | GitLab Advisory Database (GLAD)
CVE-2024-1631 Use of Insufficiently Random Values: Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with...
userandomvaluesgitlabadvisory
https://advisories.gitlab.com/golang/helm.sh/helm/v3/CVE-2025-55199/
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion | GitLab Advisory Database...
CVE-2025-55199 Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion: A Helm contributor discovered that it was possible to craft a JSON...
https://advisories.gitlab.com/pypi/pypdf/CVE-2026-41313/
pypdf: Possible long runtimes for wrong size values in incremental mode | GitLab Advisory Database...
CVE-2026-41313 pypdf: Possible long runtimes for wrong size values in incremental mode: An attacker who uses this vulnerability can craft a PDF which leads to...
https://advisories.gitlab.com/golang/github.com/bnb-chain/tss-lib/CVE-2022-47931/
Collision of hash values in github.com/bnb-chain/tss-lib | GitLab Advisory Database (GLAD)
CVE-2022-47931 Collision of hash values in github.com/bnb-chain/tss-lib: IO FinNet tss-lib before 2.0.0 allows a collision of hash values.
https://docs.gitlab.com/ja-jp/charts/development/validation/
Validations of values using JSON Schema | GitLab Docs
GitLab product documentation.
json schemavalidationsvaluesusinggitlab
https://advisories.gitlab.com/maven/org.springframework.graphql/spring-graphql/CVE-2023-34047/
Spring for GraphQL may be exposed to GraphQL context with values from a different session | GitLab...
CVE-2023-34047 Spring for GraphQL may be exposed to GraphQL context with values from a different session: A batch loader function in Spring for GraphQL...
https://advisories.gitlab.com/pypi/pypdf/CVE-2026-41168/
pypdf has long runtimes for wrong size values in cross-reference and object streams | GitLab...
CVE-2026-41168 pypdf has long runtimes for wrong size values in cross-reference and object streams: An attacker who uses this vulnerability can craft a PDF...