logo

GitLab Releases Critical Patch Updates to Address Multiple High-Severity Vulnerabilities

ID: 9eb1ea5a-3111-54db-b723-f7d134260a67

STIX ID: report--9eb1ea5a-3111-54db-b723-f7d134260a67

Feed Name: The Cyber Express

Threat Score
65/100

Date Published: 2026-01-23

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

GitLab released patch updates (18.8.2, 18.7.2, 18.6.4) for CE and EE that remediate multiple high- and medium-severity vulnerabilities—notably CVE-2025-13927 (Jira Connect DoS), CVE-2025-13928 (Releases API DoS), and CVE-2026-0723 (2FA bypass)—affecting a wide range of versions; GitLab.com is already patched, self-managed instances should prioritize upgrading (noting required database migrations and potential downtime for single-node installs) to reduce exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.