Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

GitLab Patches Multiple Vulnerabilities that Allows Attackers to Trigger XSS and DoS Attack

Posted on December 11, 2025December 11, 2025 By CWS

Crucial safety patches on December 10, 2025, addressing ten important vulnerabilities throughout its Group Version and Enterprise Version platforms.

GitLab has launched up to date variations 18.6.2, 18.5.4, and 18.4.6 to handle a number of high-severity safety points.

Excessive-Severity Threats Recognized

4 vulnerabilities obtained high-severity scores and require fast remediation.

The vulnerability panorama consists of 4 high-severity flaws, 5 medium-severity points, and one low-severity vulnerability.

4 of the important points contain cross-site scripting (XSS) assaults and improper encoding that would enable unauthorized actions on behalf of different customers.

CVE IDVulnerability TypeCVSS ScoreCVE-2025-12716Cross-site Scripting (XSS)8.7CVE-2025-8405Improper Encoding / HTML Injection8.7CVE-2025-12029Cross-site Scripting (XSS)8.0CVE-2025-12562Denial of Service (DoS)7.5CVE-2025-11984Authentication Bypass6.8CVE-2025-4097Denial of Service (DoS)6.5CVE-2025-14157Denial of Service (DoS)6.5CVE-2025-11247Information Disclosure4.3CVE-2025-13978Information Disclosure4.3CVE-2025-12734HTML Injection3.5

GitLab strongly recommends all self-managed installations improve instantly, as GitLab.com already runs the patched model.

Essentially the most extreme vulnerabilities embody a cross-site scripting flaw in Wiki performance and improper encoding in vulnerability studies, each with a CVSS rating of 8.7.

Moreover, an XSS vulnerability in Swagger UI (CVSS 8.0) and a GraphQL denial-of-service challenge (CVSS 7.5) pose important dangers.

The GraphQL vulnerability significantly issues unauthenticated attackers who can craft queries bypassing complexity limits to set off service disruptions.

An authentication bypass affecting WebAuthn two-factor-authentication customers poses a medium-severity risk. Enabling authenticated attackers to bypass safety controls.

Three denial-of-service vulnerabilities goal ExifTool processing, Commit API, and GraphQL endpoints, probably disrupting service availability.

Further points embody info disclosure via error messages and HTML injection in merge request titles.

Customers operating variations earlier than 18.4.6, 18.5.x earlier than 18.5.4, or 18.6.x earlier than 18.6.2 are weak to those exploits.

The patch consists of database migrations that will affect improve timelines. Single-node situations will expertise downtime throughout migration completion.

 Correctly configured multi-node deployments can apply updates with out service interruption utilizing zero-downtime procedures.

Organizations ought to prioritize these updates as a part of common safety hygiene practices. GitLab Devoted prospects don’t require motion.

Further particulars concerning affected model ranges and particular patch notes can be found within the official GitLab launch documentation.

Comply with us on Google Information, LinkedIn, and X to Get Extra Immediate Updates, Set CSN as a Most well-liked Supply in Google.

Cyber Security News Tags:Attack, Attackers, DoS, GitLab, Multiple, Patches, Trigger, Vulnerabilities, XSS

Post navigation

Previous Post: High-Severity Jenkins Vulnerability Allows Unauthenticated DoS via HTTP CLI
Next Post: WIRTE Leverages AshenLoader Sideloading to Install the AshTag Espionage Backdoor

Related Posts

Quttera Launches “Evidence-as-Code” API to Automate Security Compliance for SOC 2 and PCI DSS v4.0 Cyber Security News
Amp’ed RF BT-AP 111 Bluetooth Access Point Vulnerability Let Attackers Gain Full Admin Access Cyber Security News
Anatsa Android Banking Malware from Google Play Targeting Users in the U.S. and Canada Cyber Security News
5 Immediate Steps to be Followed After Clicking on a Malicious Link Cyber Security News
AWS Organizations Mis-scoped Managed Policy Let Hackers To Take Full AWS Organization Control Cyber Security News
Chinese APT Group IT Service Provider Leveraging Microsoft Console Debugger to Exfiltrate Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hundreds of Exposed Clawdbot Gateways Leave API Keys and Private Chats Vulnerable
  • Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware
  • Access System Flaws Enabled Hackers to Unlock Doors at Major European Firms
  • Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code
  • Nova Ransomware Allegedly Claiming Breach of KPMG Netherlands

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hundreds of Exposed Clawdbot Gateways Leave API Keys and Private Chats Vulnerable
  • Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware
  • Access System Flaws Enabled Hackers to Unlock Doors at Major European Firms
  • Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code
  • Nova Ransomware Allegedly Claiming Breach of KPMG Netherlands

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark