GitLab Patches Multiple Vulnerabilities that Allows Attackers to Trigger XSS and DoS Attack
ID: 882592ea-da99-5ced-a568-b7d6d31f7987
STIX ID: report--882592ea-da99-5ced-a568-b7d6d31f7987
Feed Name: cybersecurityNews.com
Threat Score
GitLab released patch releases (18.6.2, 18.5.4, 18.4.6) on 2025-12-10 to fix ten vulnerabilities—four high-severity (including XSS in Wiki and Swagger UI and improper encoding in vulnerability reports, CVSS up to 8.7), several DoS flaws, and an authentication bypass affecting WebAuthn—advising all self-managed installations to upgrade immediately while noting potential downtime for single-node migrations and that GitLab.com is already patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
