In Argo CD versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 a high severity vulnerability CVE-2025-59531 was detected. This vulnerability allows unauthenticated attackers to cause a denial-of-service (DoS) condition by sending a malformed Bitbucket Server webhook payload to the `/api/webhook` endpoint when `webhook.bitbucketserver.secret` is not configured, causing the Argo CD server process to crash and potentially triggering a full API outage. To address this issue, users should upgrade Argo CD to versions 2.14.20, 3.2.0-rc2, 3.1.8 or 3.0.19. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-59531.
Read more Developer ToolsIn Argo CD versions between 2.1.0 and 2.14.19, 3.2.0-rc1, 3.1.0-rc1 through 3.1.7, and 3.0.0-rc1 through 3.0.18 a high severity vulnerability CVE-2025-55191 was detected. This vulnerability allows authenticated attackers with repository permissions to trigger a race condition in the repository credentials handler, causing the Argo CD server to panic and crash, leading to denial-of-service. To address this issue, users should upgrade Argo CD to versions 2.14.20, 3.2.0-rc2, 3.1.8, 3.0.19 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-55191.
Read more Developer ToolsIn GitLab CE/EE versions from 11.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 a high severity vulnerability CVE-2025-8014 was detected. This issue allows unauthenticated users to bypass GraphQL query complexity limits, causing uncontrolled CPU consumption and potential Denial of Service (DoS). To address this issue, users should upgrade GitLab to versions 18.2.7, 18.3.3, 18.4.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-8014.
Read more Developer ToolsIn GitLab CE/EE versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 a medium severity vulnerability CVE-2025-9958 was detected. This issue could allow Guest users to access sensitive information stored in virtual registry configurations. To address this issue, users should upgrade GitLab CE/EE to versions 18.2.7, 18.3.3, 18.4.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-9958.
Read more Developer ToolsIn GitLab CE/EE versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 a high severity vulnerability CVE-2025-9642 was detected. This issue could allow an attacker to inject malicious content through cross-site scripting (XSS), potentially leading to account takeover. To address this issue, users should upgrade GitLab CE/EE to versions 18.2.7, 18.3.3, 18.4.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-9642.
Read more Developer ToolsIn GitLab EE versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 a medium severity vulnerability CVE-2025-7691 was detected. This privilege escalation issue could allow a developer with specific group management permissions to escalate their privileges and obtain unauthorized access to additional system capabilities. To address this issue, users should upgrade GitLab EE to versions 18.2.7, 18.3.3, 18.4.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-7691.
Read more Developer ToolsIn GitLab CE/EE versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 a low severity vulnerability CVE-2025-5069 was detected. This issue could allow an authenticated user to gain unauthorized access to confidential issues by creating a project with an identical name to the victim’s project. To address this issue, users should upgrade GitLab CE/EE to versions 18.2.7, 18.3.3, 18.4.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5069.
Read more Developer ToolsIn GitLab CE/EE versions from 18.1 before 18.2.7, 18.3 before 18.3.3 and 18.4 before 18.4.1 a low severity vulnerability CVE-2025-10867 was detected. This vulnerability allows authenticated users to create a denial-of-service condition by exploiting an unprotected GraphQL API through repeated requests. To address this issue, users should upgrade GitLab CE/EE to versions 18.2.7, 18.3.3, 18.4.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-10867.
Read more Developer ToolsIn GitLab CE/EE versions before 18.2.7, 18.3 before 18.3.3 and 18.4 before 18.4.1 a high severity vulnerability CVE-2025-10858 was detected. This vulnerability allows unauthenticated users to cause a Denial of Service (DoS) condition by uploading specially crafted large JSON files. To address this issue, users should upgrade GitLab CE/EE to versions 18.2.7, 18.3.3, 18.4.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-10858.
Read more Developer Tools