Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

GitLab Patches Multiple Vulnerabilities that Allows Attackers to Trigger XSS and DoS Attack

On Thu, Dec 10, 2025, GitLab released critical security patches addressing ten significant vulnerabilities across its Community and Enterprise Edition platforms. Updated versions 18.6.2, 18.5.4, and 18.4.6 have been made available to mitigate these…

On Thu, Dec 10, 2025, GitLab released critical security patches addressing ten significant vulnerabilities across its Community and Enterprise Edition platforms. Updated versions 18.6.2, 18.5.4, and 18.4.6 have been made available to mitigate these high-severity security issues.

Four vulnerabilities have been identified as high-severity, requiring immediate remediation. The vulnerabilities comprise:

Four high-severity flaws Five medium-severity issues One low-severity vulnerability

The critical issues involve cross-site scripting ( XSS ) attacks and improper encoding, which could permit unauthorized actions on behalf of other users.

CVE ID Vulnerability Type CVSS Score

CVE-2025-12716 Cross-site Scripting (XSS) 8.7

CVE-2025-8405 Improper Encoding / HTML Injection 8.7

CVE-2025-12029 Cross-site Scripting (XSS) 8.0

Updated versions 18.6.2, 18.5.4, and 18.4.6 have been made available to mitigate these high-severity security issues.
Noah Redmond · Thehackingpost

CVE-2025-12562 Denial of Service (DoS) 7.5

CVE-2025-11984 Authentication Bypass 6.8

CVE-2025-4097 Denial of Service (DoS) 6.5

CVE-2025-14157 Denial of Service (DoS) 6.5

CVE-2025-11247 Information Disclosure 4.3

CVE-2025-13978 Information Disclosure 4.3

CVE-2025-12734 HTML Injection 3.5

Advertisement

GitLab advises all self-managed installations to upgrade promptly, as GitLab.com is already utilizing the patched version. The most severe vulnerabilities include an XSS flaw in Wiki functionality and improper encoding in vulnerability reports, each with a CVSS score of 8.7.

An XSS vulnerability in Swagger UI (CVSS 8.0) and a GraphQL denial-of-service issue (CVSS 7.5) are also notable. The GraphQL flaw is particularly concerning for unauthenticated attackers who can craft queries to bypass complexity limits, causing service disruptions.

An authentication bypass affecting WebAuthn two-factor-authentication users poses a medium-severity threat, allowing authenticated attackers to circumvent security controls. Three denial-of-service vulnerabilities target ExifTool processing, Commit API, and GraphQL endpoints, potentially disrupting service availability.

Additional issues involve information disclosure through error messages and HTML injection in merge request titles. Users with versions before 18.4.6, 18.5.x before 18.5.4, or 18.6.x before 18.6.2 are susceptible to these exploits.

The patch includes database migrations that may affect upgrade timelines. Single-node instances will experience downtime during migration completion, while properly configured multi-node deployments can apply updates without service interruption using zero-downtime procedures.

Organizations are advised to prioritize these updates as part of regular security hygiene practices. GitLab Dedicated customers do not require any action. Further details on affected version ranges and patch notes are available in the official GitLab release documentation.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories