[aphantom](https://hackerone.com/aphantom)
4 credited records · 4 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2026-7427No exploit | Allocation of Resources Without Limits or Throttling in GitLabgitlab · gitlab · CWE-770 | High7.5 | — | 0.6% | Aug 12, 2026 |
17Monitor | CVE-2026-3607No exploit | Access Control Check Implemented After Asset is Accessed in GitLabgitlab · gitlab · CWE-1280 | Medium4.3 | — | 0.4% | May 14, 2026 |
24Monitor | CVE-2026-0752No exploit | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabgitlab · gitlab · CWE-79 | Medium6.1 | — | 0.3% | Feb 25, 2026 |
25Monitor | CVE-2024-9183No exploit | Time-of-check Time-of-use (TOCTOU) Race Condition in GitLabgitlab · gitlab · CWE-367 | Medium6.4 | — | 0.2% | Dec 5, 2025 |
- CVE-2026-742730Monitor
Allocation of Resources Without Limits or Throttling in GitLab
HighCVSS 7.5No exploitEPSS 1%gitlab · gitlabAug 12, 2026
- CVE-2026-360717Monitor
Access Control Check Implemented After Asset is Accessed in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlabMay 14, 2026
- CVE-2026-075224Monitor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
MediumCVSS 6.1No exploitEPSS 0%gitlab · gitlabFeb 25, 2026
- CVE-2024-918325Monitor
Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab
MediumCVSS 6.4No exploitEPSS 0%gitlab · gitlabDec 5, 2025