In GitLab CE/EE versions 13.2 through 18.4.4, 18.5 through 18.5.2, and 18.6 before 18.6.1 a low severity vulnerability CVE-2025-13611 was detected. This vulnerability allows authenticated users with access to certain logs to obtain sensitive tokens under specific conditions due to improper handling of sensitive information in log files. To address this issue, users should upgrade GitLab to versions 18.4.5, 18.5.3, 18.6.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13611.
Read more Developer ToolsIn GitLab CE/EE versions 18.3 through 18.4.4, 18.5 through 18.5.2, and 18.6 before 18.6.1 a medium severity vulnerability CVE-2025-12653 was detected. This vulnerability could allow unauthenticated users to join arbitrary organizations by manipulating headers in certain requests under specific conditions. To address this issue, users should upgrade GitLab to versions 18.4.5, 18.5.3, 18.6.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12653.
Read more Developer ToolsIn GitLab CE/EE versions 8.3 through 18.4.4, 18.5 through 18.5.2, and 18.6 before 18.6.1 a medium severity vulnerability CVE-2025-7449 was detected. This vulnerability allows authenticated users with specific permissions to cause a denial of service (DoS) condition through HTTP response processing. To address this issue, users should upgrade GitLab to versions 18.4.5, 18.5.3, 18.6.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-7449.
Read more Developer ToolsIn GitLab CE/EE versions 17.10 through 18.4.4, 18.5 through 18.5.2, and 18.6 before 18.6.1 a high severity vulnerability CVE-2025-12571 was detected. This vulnerability allows unauthenticated users to cause a denial of service (DoS) by sending specially crafted requests containing malicious JSON payloads. To address this issue, users should upgrade GitLab to versions 18.4.5, 18.5.3, 18.6.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12571.
Read more Developer ToolsIn GitLab EE versions 13.7 through 18.4.4, 18.5 through 18.5.2, and 18.6 before 18.6.1 a medium severity vulnerability CVE-2025-6195 was detected. This vulnerability could allow authenticated users to view information from security reports under certain configuration conditions. To address this issue, users should upgrade GitLab to versions 18.4.5, 18.5.3, 18.6.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6195.
Read more Developer ToolsIn Terraform Enterprise versions prior to 1.1.1 and 1.0.3 a medium severity vulnerability CVE-2025-13432 was detected. This vulnerability allows users with specific but insufficient permissions to create Terraform state versions in a workspace, potentially enabling infrastructure alteration if a subsequent plan operation is approved or auto-applied. To address this issue, users should upgrade Terraform Enterprise to versions 1.1.1, 1.0.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13432.
Read more Developer ToolsIn GitLab CE/EE versions 13.7 through 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 a medium severity vulnerability CVE-2025-9825 was detected. This issue allows authenticated users without project membership to access sensitive manual CI/CD variables by querying the GraphQL API. These variables may contain confidential configuration details intended only for project members. To address this issue, users should upgrade GitLab to versions 18.2.9, 18.3.4, 18.4.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-9825.
Read more Developer ToolsGitLab CE/EE versions 16.7 through 18.3.5, 18.4 through 18.4.3, and 18.5 through 18.5.1 contain a medium severity vulnerability CVE-2025-2615. This vulnerability could allow a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections. To address this issue, users should upgrade GitLab to version 18.3.6, 18.4.4, 18.5.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2615.
Read more Developer ToolsIn GitLab CE/EE versions 13.2 through 18.3.5, 18.4 through 18.4.3 and 18.5 through 18.5.1 a medium severity vulnerability CVE-2025-6171 was detected. This vulnerability allows authenticated attackers with reporter access to view branch names and pipeline details via the packages API endpoint, even when repository access is disabled. To address this issue, users should upgrade GitLab to versions 18.3.6, 18.4.4, 18.5.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6171.
Read more Developer Tools