logo

GitLab Patches Multiple Vulnerabilities that Allows Attackers to Trigger XSS and DoS Attack

ID: 882592ea-da99-5ced-a568-b7d6d31f7987

STIX ID: report--882592ea-da99-5ced-a568-b7d6d31f7987

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-11

Date Updated: 2026-04-21

Author: Abinaya

...
...

GitLab released patch releases (18.6.2, 18.5.4, 18.4.6) on 2025-12-10 to fix ten vulnerabilities—four high-severity (including XSS in Wiki and Swagger UI and improper encoding in vulnerability reports, CVSS up to 8.7), several DoS flaws, and an authentication bypass affecting WebAuthn—advising all self-managed installations to upgrade immediately while noting potential downtime for single-node migrations and that GitLab.com is already patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.