Known Vulnerabilities for Runner by Gitlab
Listed below are 3 of the newest known vulnerabilities associated with "Runner" by "Gitlab".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-105767 json | Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of C... | Not Provided | 2026-10-05 | 2026-10-05 |
| CVE-2026-103754 json | A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the wo... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-100650 json | vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls (the... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-100369 json | CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and ... | Not Provided | 2026-09-25 | 2026-09-28 |
| CVE-2026-97225 json | A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers... | Not Provided | 2026-09-24 | 2026-09-25 |
| CVE-2026-91836 json | A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_s... | Not Provided | 2026-09-15 | 2026-09-20 |
| CVE-2026-91835 json | A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file ... | Not Provided | 2026-09-15 | 2026-09-15 |
| CVE-2026-89066 json | Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 mi... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-84724 json | An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The syste... | Not Provided | 2026-09-23 | 2026-09-26 |
| CVE-2026-77602 json | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From ... | Not Provided | 2026-09-23 | 2026-09-29 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gitlab | Runner | 9.5.1 | |||
| Application | Gitlab | Runner | 9.5.0 | |||
| Application | Gitlab | Runner | 9.5.0 | |||
| Application | Gitlab | Runner | 9.4.3 | |||
| Application | Gitlab | Runner | 9.4.2 | |||
| Application | Gitlab | Runner | 9.4.1 | |||
| Application | Gitlab | Runner | 9.4.0 | |||
| Application | Gitlab | Runner | 9.4.0 | |||
| Application | Gitlab | Runner | 9.4.0 | |||
| Application | Gitlab | Runner | 9.4.0 | |||
| Application | Gitlab | Runner | 9.3.0 | |||
| Application | Gitlab | Runner | 9.3.0 | |||
| Application | Gitlab | Runner | 9.3.0 | |||
| Application | Gitlab | Runner | 9.2.2 | |||
| Application | Gitlab | Runner | 9.2.1 | |||
| Application | Gitlab | Runner | 9.2.0 | |||
| Application | Gitlab | Runner | 9.2.0 | |||
| Application | Gitlab | Runner | 9.2.0 | |||
| Application | Gitlab | Runner | 9.1.3 | |||
| Application | Gitlab | Runner | 9.1.2 |