HomeSecurityGitLab Security Update – Fixing Multiple Vulnerabilities

GitLab Security Update – Fixing Multiple Vulnerabilities

GitLab has released important security updates. The new releases are 18.4.2, 18.3.4 , and 18.2.8 for Community (CE) and Enterprise Edition (EE). These updates fix several vulnerabilities that could lead to denial of service (DoS) attacks and allow unauthorized access.

See also: GitLab security update fixes multiple vulnerabilities

GitLab

All user-managed GitLab installations are recommended to be upgraded immediately to mitigate potential outages. GitLab.com and GitLab Dedicated are already fully protected by these updates. The patched versions address several new vulnerabilities that affect both authenticated and unauthenticated users.

These issues, which span multiple attack vectors, highlight the ongoing risk to code repositories and development pipelines if left unpatched. GitLab's standard practice is to ensure that issues are only publicly documented 30 days after the update is deployed, emphasizing the need for proactive upgrades to maintain security.

Security researchers and GitLab's internal team have identified four main issues in this update, each of which presents unique risks:

See also: DevSecOps: GitLab fixes multiple vulnerabilities

GitLab Security Update – Fixing Multiple Vulnerabilities
  • CVE-2025-11340 : GraphQL Mutation Authorization Bypass . This high severity (CVSS 7.7) vulnerability allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerable files due to incorrect scope in GraphQL mutations. Exploitation could lead to falsification of vulnerability details, burdening governance and compliance efforts. Affected versions include GitLab EE 18.3 through 18.3.4 and 18.4 through 18.4.2 .
  • CVE-2025-10004: Denial of Service via GraphQL Blob. With a CVSS score of 7.5, this remote vulnerability affected versions 13.12 through 18.2.8, 18.3 through 18.3.4 , and 18.4 through 18.4.2. By sending specially crafted GraphQL requests for large repository blobs, attackers could exhaust server resources, rendering a GitLab installation unresponsive. No authentication is required, significantly expanding the attack surface.
  • CVE-2025-9825: Unauthorized Access to Manual CI/CD Variables via GraphQL. This medium severity (CVSS 5.0) bug exposed sensitive manual CI/CD variables to authenticated users who were not members of the project, simply by querying the GraphQL API. Affected versions range from 13.7 to 18.2.8, and pre-patched versions of 18.3 and 18.4.
  • CVE-2025-2934: DoS via Malicious Webhook in GitLab CE/EE. Affecting all versions from 5.2 to 18.2.8, 18.3 before 18.3.4 , and 18.4 before 18.4.2, this moderate risk (CVSS 4.3) resulted from an error in the Ruby Core library. Attackers could configure webhooks to send malicious HTTP responses, destabilizing GitLab servers.

The issue was responsibly disclosed in July 2025. GitLab strongly urges all organizations running self-managed or on-premise deployments to upgrade to new releases immediately to avoid system outages and unauthorized data manipulation. Delaying updates increases the risks of outages, data leakage, and escalation attacks via exploits.

See also: GitLab Duo vulnerability allows manipulation of AI responses

gitlab cisa

GitLab provides best practices and upgrade guidelines in its official releases and security blogs. Maintaining timely patch hygiene is essential for development teams and enterprises that rely on GitLab for source code management, CI/CD, and collaborative software workflows.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS