CVE-2025-14870Patch(gitlab / gitlab)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gitlab gitlab systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted JSON payloads due to insufficient input validation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-14: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-14: 105-14
Signal classification1 categories
Patch
1100.0%
Referenced assets2 URLs
Full discourse1 post
  • yousukezan@yousukezan
    Patch

    GitLabは2026年5月13日、複数の高深刻度脆弱性へ対処する緊急アップデートを公開した。特に深刻なのはCVSS 8.7のXSS脆弱性CVE-2026-7481、CVE-2026-5297、CVE-2026-6073で、分析ダッシュボード、グローバル検索、Duo Agent出力へ悪意あるJavaScriptを注入できる。 開発者が閲覧するとスクリプトが自動実行され、セッション乗っ取りや認証トークン窃取、リポジトリ改ざんにつながる可能性がある。 加えて、認証不要DoS脆弱性CVE-2026-1659、CVE-2025-14870、CVE-2025-14869も修正された。CI/CDジョブ更新APIやDuo Workflows APIへ細工済みリクエストを大量送信するだけで、開発基盤を停止状態へ追い込める。コード更新やデプロイ、内部ワークフロー管理が不能になる恐れがある。 影響を受けるのはセルフホスト型のGitLab Community Edition(CE)およびEnterprise Edition(EE)で、http://GitLab.comなどクラウド版は既に修正済み。管理者には18.11.3、18.10.6、18.9.7への即時更新が推奨されている。単一ノード構成ではアップグレード時に停止が発生するが、マルチノード環境では無停止更新も可能としている。 https://cybersecuritynews.com/gitlab-vulnerabilities-xss-and-dos/

    Post summary

    The article announces critical GitLab vulnerabilities, details their technical nature, and recommends specific patch updates to mitigate the issues.

    011037134.5K
    14.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---

Explore more