In GitLab CE/EE versions 16.9 through 18.3.5, 18.4 through 18.4.3, and 18.5 through 18.5.1 a low severity vulnerability CVE-2025-12983 was detected. This vulnerability allows authenticated attackers to trigger a denial of service condition by submitting specially crafted markdown content containing nested formatting patterns. To address this issue, users should upgrade GitLab to versions 18.3.6, 18.4.4, 18.5.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12983.
Read more Developer ToolsIn GitLab CE/EE versions 17.9 through 18.3.5, 18.4 through 18.4.3, and 18.5 through 18.5.1 a low severity vulnerability CVE-2025-7736 was detected. This vulnerability allows authenticated attackers to bypass access control restrictions and access GitLab Pages content intended only for project members by authenticating through OAuth providers. To address this issue, users should upgrade GitLab to versions 18.3.6, 18.4.4, 18.5.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-7736.
Read more Developer ToolsIn GitLab CE/EE versions 17.6 through 18.3.5, 18.4 through 18.4.3, and 18.5 through 18.5.1 a medium severity vulnerability CVE-2025-7000 was detected. This vulnerability could allow unauthorized users to view confidential branch names by accessing project issues associated with related merge requests under specific conditions. To address this issue, users should upgrade GitLab to versions 18.3.6, 18.4.4, 18.5.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-7000.
Read more Developer ToolsIn GitLab EE versions 17.8 through 18.3.5, 18.4 through 18.4.3 and 18.5 through 18.5.1 a low severity vulnerability CVE-2025-6945 was detected. This vulnerability allows authenticated attackers to leak sensitive information from confidential issues by injecting hidden prompts into merge request comments. To address this issue, users should upgrade GitLab to versions 18.3.6, 18.4.4, 18.5.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6945.
Read more Developer ToolsIn GitHub Enterprise Server versions prior to 3.18.1, 3.17.7, 3.16.10, 3.15.14, and 3.14.19 a high severity vulnerability CVE-2025-11892 was detected. This vulnerability allows a DOM-based cross-site scripting (XSS) via the Issues search label filter that could lead to privilege escalation and unauthorized workflow triggers when an attacker entices a user in sudo mode to click a crafted link. To fix this vulnerability, users should upgrade GitHub Enterprise Server to versions 3.18.1, 3.17.7, 3.16.10, 3.15.14 or 3.14.19 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-11892.
Read more Developer ToolsIn GitHub Enterprise Server versions prior to 3.19 a high severity vulnerability CVE-2025-11578 was detected. This vulnerability allows an authenticated Enterprise admin to gain root SSH access to the appliance by exploiting a symlink escape in pre-receive hook environments. By crafting a malicious repository and environment, an attacker could replace system binaries during hook cleanup and execute a payload that adds their SSH key to the root user’s authorized keys, granting full root access. To fix this vulnerability, users should upgrade GitHub Enterprise Server to versions 3.14.19, 3.15.14, 3.16.10, 3.17.7, 3.18.1, or 3.19 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-11578.
Read more Developer ToolsIn ZITADEL versions 4.0.0-rc.1 through 4.6.2 a high severity vulnerability CVE-2025-64431 was detected. This vulnerability allows authenticated users with specific administrator roles in one organization to access or modify organization-level data (such as name, domains, and metadata) of other organizations via insecure direct object reference (IDOR) in the V2Beta API, leading to cross-tenant data tampering. To address this issue, users should upgrade ZITADEL to version 4.6.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-64431.
Read more Developer ToolsIn Kubernetes C# client versions prior to 17.0.14 a medium severity vulnerability CVE-2025-9708 was detected. This vulnerability allows the client to accept certificates from any Certificate Authority (CA) without properly validating the trust chain in custom CA mode, which may allow a malicious actor to present a forged certificate and perform man-in-the-middle attacks or API impersonation. To fix this vulnerability, users should upgrade to version 17.0.14 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-9708.
Read more Developer ToolsIn GitLab EE versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 a high severity vulnerability CVE-2025-11702 was detected. This vulnerability allows an authenticated attacker with specific permissions to hijack project runners from other projects. To fix this vulnerability, users should upgrade to GitLab versions 18.5.1, 18.4.3, or 18.3.5. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-11702.
Read more Developer Tools