GitLab Releases Critical Patch Updates to Address Multiple High-Severity Vulnerabilities
ID: 9eb1ea5a-3111-54db-b723-f7d134260a67
STIX ID: report--9eb1ea5a-3111-54db-b723-f7d134260a67
Feed Name: The Cyber Express
Threat Score
GitLab released patch updates (18.8.2, 18.7.2, 18.6.4) for CE and EE that remediate multiple high- and medium-severity vulnerabilities—notably CVE-2025-13927 (Jira Connect DoS), CVE-2025-13928 (Releases API DoS), and CVE-2026-0723 (2FA bypass)—affecting a wide range of versions; GitLab.com is already patched, self-managed instances should prioritize upgrading (noting required database migrations and potential downtime for single-node installs) to reduce exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
