Articles
Newsflash
16 Jun 2025 DevOps
Spring Framework: Reflected File Download via Unsanitized Filename in Content-Disposition Header

In Spring Framework versions 6.0.5 to 6.0.28, 6.1.0 to 6.1.20 and 6.2.0 to 6.2.7 a medium severity vulnerability CVE-2025-41234 was detected. This vulnerability allows remote attackers to perform reflected file download (RFD) attacks by injecting malicious commands through unsanitized user input passed to `ContentDisposition.Builder#filename(String, Charset)` using a non-ASCII charset. To address this issue, users should upgrade Spring Framework to versions 6.0.29 (Commercial), 6.1.21 or 6.2.8. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-41234.

Read more
Application Development
16 Jun 2025 DevOps
GitLab CE/EE: Denial of Service via Improper Input Validation in Token Names

In GitLab CE/EE versions from 8.7 before 17.10.8, 17.11 before 17.11.4 and 18.0 before 18.0.2 a medium severity vulnerability CVE-2025-1516 was detected. This vulnerability allows attackers to trigger a denial of service due to improper input validation in token names. To address this issue, users should upgrade GitLab CE/EE to versions 17.10.8, 17.11.4 or 18.0.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1516.

Read more
Developer Tools
16 Jun 2025 DevOps
GitLab CE/EE: Denial of Service via Improper Input Validation in Board Names

In GitLab CE/EE versions from 8.13 before 17.10.7, 17.11 before 17.11.3 and 18.0 before 18.0.1 a medium severity vulnerability CVE-2025-1478 was detected. This vulnerability allows attackers to trigger a denial of service due to lack of input validation in board names. To address this issue, users should upgrade GitLab CE/EE to versions 17.10.7, 17.11.3 or 18.0.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1478.

Read more
Developer Tools
16 Jun 2025 DevOps
GitLab CE/EE: Infinite Redirect Loop Leading to Denial of Service

In GitLab CE/EE versions from 17.7 before 17.10.8, 17.11 before 17.11.4 and 18.0 before 18.0.2 a high severity vulnerability CVE-2025-0673 was detected. This vulnerability allows attackers to trigger an infinite redirect loop, potentially leading to a denial of service condition. To address this issue, users should upgrade GitLab CE/EE to versions 17.10.8, 17.11.4 or 18.0.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0673.

Read more
Developer Tools
16 Jun 2025 DevOps
GitLab EE: Private Repository Clone Possible via Race Condition on Out-of-Sync Secondary Node

In GitLab EE versions prior to 17.10.8, 17.11 before 17.11.4 and 18.0 before 18.0.2 a medium severity vulnerability CVE-2024-9512 was detected. This vulnerability allows attackers to clone a private repository due to a race condition when a secondary node is out of sync. To address this issue, users should upgrade GitLab EE to versions 17.10.8, 17.11.4 or 18.0.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-9512.

Read more
Developer Tools
13 Jun 2025 DevOps
GitLab: DoS via Improper Input Validation in HTTP Responses

In GitLab CE/EE versions from 2.1.0 up to and including 17.10.7, 17.11.0 to 17.11.3 and 18.0.0 to 18.0.1 a medium severity vulnerability CVE-2025-5996 was detected. This vulnerability allows authenticated attackers to cause a denial of service due to insufficient input validation in HTTP responses. To address this issue, users should upgrade GitLab CE/EE to versions 17.10.8, 17.11.4 or 18.0.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5996.

Read more
Developer Tools
Case Studies