GitLab product security update advisory

GitLab product security update advisory

Overview


A security update has been released to address vulnerabilities in GitLab products. users of these products should update to the latest version of the patch.

Affected Products and Versions


  • CVE-2025-14869, CVE-2025-14870: GitLab CE/EE 18.5 and later but not earlier than 18.9.7, 18.10 and later but not earlier than 18.10.6, 18.11 and later but not earlier than 18.11.3.
  • CVE-2026-1659: GitLab CE/EE 9.0 and later less than 18.9.7, 18.10 and later less than 18.10.6, 18.11 and later less than 18.11.3.
  • CVE-2026-6073, CVE-2026-7377: GitLab EE 18.7 or later less than 18.9.7, 18.10 or later less than 18.10.6, 18.11 or later less than 18.11.3.

Resolved Vulnerabilities


  • Denial of Service (DoS, causing service disruption) vulnerabilities in GitLab CE/EE: CVE-2025-14869, CVE-2025-14870, CVE-2026-1659.
  • Cross-site scripting (XSS, injecting malicious scripts into web pages) vulnerabilities in GitLab EE: CVE-2026-6073, CVE-2026-7377.

Patch versions


  • Cve-2025-14869, cve-2025-14870: 18.9.7, 18.10.6, 18.11.3.
  • Cve-2026-1659: 18.9.7, 18.10.6, 18.11.3.
  • Cve-2026-6073, cve-2026-7377: 18.9.7, 18.10.6, 18.11.3.

Notes


GitLab Patch Release: 18.11.3, 18.10.6, 18.9.7 guidance was provided.