Critical GitLab Vulnerabilities Enables XSS and Unauthenticated DoS Attacks
ID: 4b9e08cf-2017-5479-ae20-9f2a7e62ae6e
STIX ID: report--4b9e08cf-2017-5479-ae20-9f2a7e62ae6e
Feed Name: cybersecurityNews.com
GitLab released emergency security updates addressing multiple high-severity vulnerabilities—primarily Cross-Site Scripting (CVE-2026-7481, CVE-2026-5297, CVE-2026-6073) and unauthenticated Denial-of-Service flaws (CVE-2026-1659, CVE-2025-14870, CVE-2025-14869)—that can enable session hijacking, token theft, or paralysis of CI/CD pipelines; self-managed CE/EE instances must upgrade immediately to versions 18.11.3, 18.10.6, or 18.9.7, noting single-node upgrades require downtime while multi-node upgrades can be zero-downtime.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
