HomeUpdatesGitLab fixed 10 security vulnerabilities

GitLab fixed 10 security vulnerabilities

GitLab has released critical security updates, fixing ten vulnerabilities affecting both Community Edition (CE) and Enterprise Edition (EE). The new versions 18.6.2, 18.5.4 , and 18.4.6 promise to address vulnerabilities rated as high severity , requiring immediate action from system administrators.

GitLab vulnerabilities

Ten vulnerabilities – Four of high severity

At the heart of the update are four high-severity vulnerabilities that could allow attackers to perform malicious actions on behalf of other users. In total, GitLab lists:

  • 4 high severity vulnerabilities
  • 5 vulnerabilities of moderate severity
  • 1 low severity vulnerability

The most worrisome vulnerabilities are related to cross-site scripting (XSS) and improper encoding, which open the way to unauthorized changes and attempts to intercept information.

See also: Chrome fixes serious zero-day vulnerability

The most serious defects that were fixed

The most serious vulnerabilities include a cross-site scripting in Wiki functionality and improper encoding in vulnerability reports (CVSS score 8.7).

Additionally, an XSS vulnerability in Swagger UI (CVSS 8.0) and a GraphQL denial-of-service (CVSS 7.5) pose significant risks.

The GraphQL vulnerability is particularly concerning for unauthorized attackers who can create queries bypassing complexity limits to cause service disruptions.

See also: Microsoft Patch Tuesday December 2025 released

GitLab fixed 10 security vulnerabilities

WebAuthn vulnerabilities and additional DoS issues

A moderate severity vulnerability affects the WebAuthn 2FA, where malicious users with limited access can bypass critical authentication checks. While exploitation requires certain prerequisites, the issue is considered essential for organizations that rely on WebAuthn as a core security scheme.

The patch additionally addresses three DoS vulnerabilities that affect:

  • ExifTool processing
  • the Commit API
  • GraphQL endpoints

These vulnerabilities could result in partial or complete service disruption, causing delays or even outages of GitLab instances.

See also: Zero-day Gogs vulnerability used in attacks

More fixes: Information leaks and HTML injection

Among the issues resolved are:

  • HTML injection in merge request titles, which could be used to phish internal users or CI/CD environments

GitLab points out that any installation that uses versions:

  • before 18.4.6
  • 18.5.x before 18.5.4
  • 18.6.x before 18.6.2

is in immediate danger and requires urgent upgrading.

GitLab fixed 10 security vulnerabilities

Possible downtime due to database migration

The new updates include database migrations, which may impact the upgrade schedule. Single node instances will experience mandatory downtime.

Multi-node clusters that are properly configured can perform non-disruptive upgrades through zero-downtime deployment processes.

Organizations that rely on GitLab for DevOps, CI/CD, and collaboration should integrate these updates immediately.

What users should do

GitLab.com customers do not need to take any action, as the platform is already running the updated versions. However, those managing self-hosted installations should proceed with the upgrade immediately, following the instructions in the official documentation .

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS