Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Multiple Gitlab Security Vulnerabilities Let Attackers Trigger DoS Condition

GitLab has released urgent updates for its Community Edition (CE) and Enterprise Edition (EE) to address multiple critical security vulnerabilities. The patch versions 18.5.1, 18.4.3, and 18.3.5 resolve several high-severity denial-of-service (DoS)…

GitLab has released urgent updates for its Community Edition (CE) and Enterprise Edition (EE) to address multiple critical security vulnerabilities. The patch versions 18.5.1, 18.4.3, and 18.3.5 resolve several high-severity denial-of-service (DoS) vulnerabilities.

The updates fix issues related to specially crafted payloads that can overwhelm systems, as well as access control and authorization bugs affecting authenticated users. GitLab recommends immediate upgrades for all self-managed installations. GitLab.com users and Dedicated customers are not affected.

CVE-2025-10497: Affects event collection, allowing unauthenticated users to send crafted payloads that exhaust resources. This vulnerability impacts CE/EE versions from 17.10 and carries a CVSS score of 7.5. CVE-2025-11447: Exploits JSON validation in GraphQL requests, enabling unauthenticated actors to flood systems with malicious payloads starting from version 11.0. It also has a CVSS score of 7.5. CVE-2025-11974: Occurs during file uploads to specific API endpoints, where large files from unauthenticated sources consume excessive resources. It affects versions from 11.7 and has a CVSS score of 6.5.

These vulnerabilities were reported through GitLab's HackerOne program or discovered internally, highlighting exposure to event processing, data validation, and upload mechanisms.

GitLab has released urgent updates for its Community Edition (CE) and Enterprise Edition (EE) to address multiple critical security vulnerabilities.
Chloe Simmons · Thehackingpost

CVE-2025-11702: A high-severity improper access control in the runner API for EE, allowing authenticated users to hijack runners across projects (CVSS 8.5). CVE-2025-11971: Fixes incorrect authorization in CE pipeline builds, allowing unauthorized executions via commit manipulation (CVSS 6.5). Lower-severity issues include business logic errors in EE group memberships (CVE-2025-6601, CVSS 3.8) and missing authorizations in quick actions (CVE-2025-11989, CVSS 3.7).

The patches are part of GitLab's biannual update schedule, with full details available 30 days post-release on their issue tracker. Additional bug fixes address Redis gem downgrades, connection pool errors, and Geo routing leaks.

Advertisement

GitLab strongly advises upgrading all affected self-managed instances immediately to mitigate these risks. This applies to Omnibus, source, and Helm deployments. Regular patching is essential for maintaining security, as outlined in GitLab's handbook. No exploits have been reported, but proactive updates can prevent potential disruptions.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories