Cyber Security News

Multiple GitLab Vulnerabilities Enables 2FA Bypass and DoS Attacks

Critical security patches addressing five vulnerabilities across versions 18.8.2, 18.7.2, and 18.6.4 for both Community Edition (CE) and Enterprise Edition (EE).

The patches resolve issues ranging from high-severity authentication flaws to denial-of-service conditions affecting core platform functionality.

Critical 2FA Bypass Vulnerability

The most severe vulnerability is CVE-2026-0723, an unchecked return value issue in authentication services enabling two-factor authentication bypass.

An attacker with knowledge of a victim’s credential ID could bypass 2FA protections by submitting forged device responses, potentially gaining unauthorized access to user accounts.

This vulnerability affects versions 18.6 through 18.8 and carries a CVSS score of 7.4, indicating high risk for confidentiality and integrity breaches.

CVE IDVulnerability TypeSeverityCVSS ScoreAffected VersionsImpact
CVE-2026-0723Unchecked Return Value in AuthenticationHigh7.418.6–18.8.x2FA bypass via forged device responses
CVE-2025-13927DoS in Jira Connect IntegrationHigh7.511.9–18.8.xUnauthenticated service disruption
CVE-2025-13928Incorrect Authorization in Releases APIHigh7.517.7–18.8.xUnauthorized DoS via API endpoint
CVE-2025-13335Infinite Loop in Wiki RedirectsMedium6.517.1–18.8.xAuthenticated user DoS via malformed Wiki docs
CVE-2026-1102DoS in API EndpointMedium5.312.3–18.8.xUnauthenticated DoS via SSH authentication

Authorization and DoS Vulnerabilities

CVE-2025-13927 and CVE-2025-13928 represent critical denial-of-service threats.

CVE-2025-13927 exploits the Jira Connect integration, allowing unauthenticated users to craft malformed authentication requests that disrupt service.

CVE-2025-13928 involves incorrect authorization validation in the Releases API, enabling unauthorized DoS conditions.

Both carry CVSS scores of 7.5 and affect extensive version ranges from 11.9 to 17.7, respectively.

CVE-2025-13335 involves an infinite loop vulnerability in Wiki redirects that authenticated users can exploit by submitting malformed Wiki documents that bypass cycle detection.

CVE-2026-1102 targets the API endpoint through repeated malformed SSH authentication requests from unauthenticated sources, with a lower CVSS of 5.3 but broader affected versions from 12.3 onward.

GitLab strongly recommends immediate upgrades for all self-managed installations. GitLab.com users are already protected, and Dedicated customers require no action.

Database migrations may cause downtime on single-node instances, though multi-node deployments can implement zero-downtime procedures. Post-deploy migrations are available for version 18.7.2.

Organizations should prioritize upgrades to address the 2FA bypass vulnerability and prevent potential account compromise. Patch notifications are available via RSS feed subscription through GitLab’s security releases channel.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

1 minute ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

6 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

12 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

17 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

28 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago