Cyber Security News

GitLab Patches Multiple Vulnerabilities that Allows Attackers to Trigger XSS and DoS Attack

Critical security patches on December 10, 2025, addressing ten significant vulnerabilities across its Community Edition and Enterprise Edition platforms.

GitLab has released updated versions 18.6.2, 18.5.4, and 18.4.6 to address multiple high-severity security issues.

High-Severity Threats Identified

Four vulnerabilities received high-severity ratings and require immediate remediation.

The vulnerability landscape includes four high-severity flaws, five medium-severity issues, and one low-severity vulnerability.

Four of the critical issues involve cross-site scripting (XSS) attacks and improper encoding that could allow unauthorized actions on behalf of other users.

CVE IDVulnerability TypeCVSS Score
CVE-2025-12716Cross-site Scripting (XSS)8.7
CVE-2025-8405Improper Encoding / HTML Injection8.7
CVE-2025-12029Cross-site Scripting (XSS)8.0
CVE-2025-12562Denial of Service (DoS)7.5
CVE-2025-11984Authentication Bypass6.8
CVE-2025-4097Denial of Service (DoS)6.5
CVE-2025-14157Denial of Service (DoS)6.5
CVE-2025-11247Information Disclosure4.3
CVE-2025-13978Information Disclosure4.3
CVE-2025-12734HTML Injection3.5

GitLab strongly recommends all self-managed installations upgrade immediately, as GitLab.com already runs the patched version.

The most severe vulnerabilities include a cross-site scripting flaw in Wiki functionality and improper encoding in vulnerability reports, both with a CVSS score of 8.7.

Additionally, an XSS vulnerability in Swagger UI (CVSS 8.0) and a GraphQL denial-of-service issue (CVSS 7.5) pose significant risks.

The GraphQL vulnerability particularly concerns unauthenticated attackers who can craft queries bypassing complexity limits to trigger service disruptions.

An authentication bypass affecting WebAuthn two-factor-authentication users poses a medium-severity threat. Enabling authenticated attackers to circumvent security controls.

Three denial-of-service vulnerabilities target ExifTool processing, Commit API, and GraphQL endpoints, potentially disrupting service availability.

Additional issues include information disclosure through error messages and HTML injection in merge request titles.

Users running versions before 18.4.6, 18.5.x before 18.5.4, or 18.6.x before 18.6.2 are vulnerable to these exploits.

The patch includes database migrations that may impact upgrade timelines. Single-node instances will experience downtime during migration completion.

 Properly configured multi-node deployments can apply updates without service interruption using zero-downtime procedures.

Organizations should prioritize these updates as part of regular security hygiene practices. GitLab Dedicated customers do not require action.

Additional details regarding affected version ranges and specific patch notes are available in the official GitLab release documentation.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

52 seconds ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

5 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

11 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

17 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

28 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago