16 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2026-1868
GitLab AI Gateway DevOps
9.9
CRITICAL
EPSS
0.0%
2026 CWE-1336 1 PoC

GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in which AI Gateway was vulnerable to insecure template expansion of user supplied data via crafted Duo Agent Platform Flow definitions. This vulnerability could be used to cause Denial of Service or gain code execution on the Gateway. This has been fixed in versions 18.6.2, 18.7.1, and 18.8.1 of the GitLab AI Gateway.

CVE-2026-28516
openDCIM DevOps Web Database
9.3
CRITICAL
EPSS
23.8%
2026 CWE-89 1 PoC

openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php handlers pass user-supplied input directly into SQL statements using string interpolation without prepared statements or proper input sanitation. An authenticated user can execute arbitrary SQL statements against the underlying database.

CVE-2026-28515
openDCIM DevOps Web Windows
9.3
CRITICAL
EPSS
44.3%
2026 CWE-862 1 PoC

openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The installer and upgrade handler expose LDAP configuration functionality without enforcing application role checks. Any authenticated user can access this functionality regardless of assigned privileges. In deployments where REMOTE_USER is set without authentication enforcement, the endpoint may be accessible without credentials. This allows unauthorized modification of application configuration.

CVE-2026-22908
TDC-X401GL DevOps
9.1
CRITICAL
EPSS
0.0%
2026 CWE-266 1 PoC

Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.

CVE-2026-0863
Software Genérico DevOps
8.5
HIGH
EPSS
0.0%
2026 CWE-95 2 PoCs

Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted Python code in the underlying operating system. The vulnerability can be exploited via the Code block by an authenticated user with basic permissions and can lead to a full n8n instance takeover on instances operating under "Internal" execution mode. If the instance is operating under the "External" execution mode (ex. n8n's official Docker image) - arbitrary code execution occurs inside a Sidecar container and not the main node, which signifi

CVE-2026-24840
dokploy DevOps Web
8.0
HIGH
EPSS
0.1%
2026 CWE-798 1 PoC

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation script (located at https://dokploy.com/install.sh, line 154) uses a hardcoded password when creating the database container. This means that nearly all Dokploy installations use the same database credentials and could be compromised. Version 0.26.6 contains a patch for the issue.

CVE-2026-0752
GitLab DevOps
8.0
HIGH
EPSS
0.1%
2026 CWE-79 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that under certain circumstances, could have allowed an unauthenticated user to inject arbitrary scripts into the Mermaid sandbox UI.

CVE-2026-30824
Flowise DevOps Web Networking ⚡ nuclei
7.7
HIGH
EPSS
9.4%
2026 CWE-306 0 PoCs

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whitelisted in the global authentication middleware, allowing unauthenticated access to privileged container management and token generation endpoints. This issue has been patched in version 3.0.13.

CVE-2026-41414
skim DevOps
7.4
HIGH
EPSS
0.0%
2026 CWE-94 1 PoC

Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.yml checks out attacker-controlled fork code and executes it via cargo run, with access to SKIM_RS_BOT_PRIVATE_KEY and GITHUB_TOKEN (contents:write). No gates prevent exploitation - any GitHub user can trigger this by opening a pull request from a fork. This vulnerability is fixed with commit bf63404ad51985b00ed304690ba9d477860a5a75.

CVE-2026-0595
GitLab DevOps
7.3
HIGH
EPSS
0.1%
2026 CWE-79 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to add unauthorized email addresses to victim accounts through HTML injection in test case titles.

CVE-2026-1458
GitLab DevOps
6.5
MEDIUM
EPSS
0.0%
2026 CWE-770 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service by uploading malicious files.

CVE-2026-1456
GitLab DevOps
6.5
MEDIUM
EPSS
0.0%
2026 CWE-770 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview.

CVE-2026-1747
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2026 CWE-288 1 PoC

GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-role users with insufficient privileges to make unauthorized modifications to protected Conan packages.

CVE-2026-0602
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2026 CWE-288 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose metadata from private issues, merge requests, epics, milestones, or commits due to improper filtering in the snippet rendering process under certain circumstances.

CVE-2026-1230
GitLab DevOps
4.1
MEDIUM
EPSS
0.1%
2026 CWE-706 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause repository downloads to contain different code than displayed in the web interface due to incorrect validation of branch references under certain circumstances.

CVE-2026-1751
GitLab DevOps
3.1
LOW
EPSS
0.0%
2026 CWE-862 1 PoC

A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.