GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks
ID: 8c2fe820-a841-55a1-8db4-1a91a1b063cd
STIX ID: report--8c2fe820-a841-55a1-8db4-1a91a1b063cd
Feed Name: cybersecurityNews.com
GitLab released critical security updates for CE/EE (versions 18.8.4, 18.7.4, 18.6.6) that address multiple high-severity vulnerabilities — most notably CVE-2025-7659 (CVSS 8.0) in the Web IDE allowing unauthenticated token theft and access to private repositories, plus DoS issues (CVE-2025-8099, CVE-2026-0958) and an XSS flaw (CVE-2025-14560). Administrators of self-managed instances are urged to upgrade immediately; GitLab.com has already been patched and upgrades may require brief downtime for migrations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
