GitLab has released critical security updates, fixing ten vulnerabilities affecting both Community Edition (CE) and Enterprise Edition (EE). The new versions 18.6.2, 18.5.4 , and 18.4.6 promise to address vulnerabilities rated as high severity , requiring immediate action from system administrators.

Ten vulnerabilities – Four of high severity
At the heart of the update are four high-severity vulnerabilities that could allow attackers to perform malicious actions on behalf of other users. In total, GitLab lists:
- 4 high severity vulnerabilities
- 5 vulnerabilities of moderate severity
- 1 low severity vulnerability
The most worrisome vulnerabilities are related to cross-site scripting (XSS) and improper encoding, which open the way to unauthorized changes and attempts to intercept information.
See also: Chrome fixes serious zero-day vulnerability
The most serious defects that were fixed
The most serious vulnerabilities include a cross-site scripting in Wiki functionality and improper encoding in vulnerability reports (CVSS score 8.7).
Additionally, an XSS vulnerability in Swagger UI (CVSS 8.0) and a GraphQL denial-of-service (CVSS 7.5) pose significant risks.
The GraphQL vulnerability is particularly concerning for unauthorized attackers who can create queries bypassing complexity limits to cause service disruptions.
See also: Microsoft Patch Tuesday December 2025 released

WebAuthn vulnerabilities and additional DoS issues
A moderate severity vulnerability affects the WebAuthn 2FA, where malicious users with limited access can bypass critical authentication checks. While exploitation requires certain prerequisites, the issue is considered essential for organizations that rely on WebAuthn as a core security scheme.
The patch additionally addresses three DoS vulnerabilities that affect:
- ExifTool processing
- the Commit API
- GraphQL endpoints
These vulnerabilities could result in partial or complete service disruption, causing delays or even outages of GitLab instances.
See also: Zero-day Gogs vulnerability used in attacks
More fixes: Information leaks and HTML injection
Among the issues resolved are:
- information leaks through error messages
- HTML injection in merge request titles, which could be used to phish internal users or CI/CD environments
GitLab points out that any installation that uses versions:
- before 18.4.6
- 18.5.x before 18.5.4
- 18.6.x before 18.6.2
is in immediate danger and requires urgent upgrading.

Possible downtime due to database migration
The new updates include database migrations, which may impact the upgrade schedule. Single node instances will experience mandatory downtime.
Multi-node clusters that are properly configured can perform non-disruptive upgrades through zero-downtime deployment processes.
Organizations that rely on GitLab for DevOps, CI/CD, and collaboration should integrate these updates immediately.
What users should do
GitLab.com customers do not need to take any action, as the platform is already running the updated versions. However, those managing self-hosted installations should proceed with the upgrade immediately, following the instructions in the official documentation .
