GitLab product security update advisory
Overview
A security update has been released to address vulnerabilities in GitLab products. users of these products should update to the latest version of the patch.
Affected Products and Versions
- CVE-2025-14869, CVE-2025-14870: GitLab CE/EE 18.5 and later but not earlier than 18.9.7, 18.10 and later but not earlier than 18.10.6, 18.11 and later but not earlier than 18.11.3.
- CVE-2026-1659: GitLab CE/EE 9.0 and later less than 18.9.7, 18.10 and later less than 18.10.6, 18.11 and later less than 18.11.3.
- CVE-2026-6073, CVE-2026-7377: GitLab EE 18.7 or later less than 18.9.7, 18.10 or later less than 18.10.6, 18.11 or later less than 18.11.3.
Resolved Vulnerabilities
- Denial of Service (DoS, causing service disruption) vulnerabilities in GitLab CE/EE: CVE-2025-14869, CVE-2025-14870, CVE-2026-1659.
- Cross-site scripting (XSS, injecting malicious scripts into web pages) vulnerabilities in GitLab EE: CVE-2026-6073, CVE-2026-7377.
Patch versions
- Cve-2025-14869, cve-2025-14870: 18.9.7, 18.10.6, 18.11.3.
- Cve-2026-1659: 18.9.7, 18.10.6, 18.11.3.
- Cve-2026-6073, cve-2026-7377: 18.9.7, 18.10.6, 18.11.3.
Notes
GitLab Patch Release: 18.11.3, 18.10.6, 18.9.7 guidance was provided.