{"id":10565,"date":"2026-02-11T10:03:42","date_gmt":"2026-02-11T10:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/11\/gitlab-patches-multiple-vulnerabilities-that-enables-dos-and-cross-site-scripting-attacks\/"},"modified":"2026-02-11T10:03:42","modified_gmt":"2026-02-11T10:03:42","slug":"gitlab-patches-multiple-vulnerabilities-that-enables-dos-and-cross-site-scripting-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/11\/gitlab-patches-multiple-vulnerabilities-that-enables-dos-and-cross-site-scripting-attacks\/","title":{"rendered":"GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks"},"content":{"rendered":"<p>    GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical security update has been released for both the Community Edition (CE) and Enterprise Edition (EE) to address multiple high-severity vulnerabilities.<\/p>\n<p>The patches, available in versions 18.8.4, 18.7.4, and 18.6.6, fix flaws that could allow attackers to crash servers, steal data, or hijack user sessions.<\/p>\n<p>Security experts urge administrators of self-managed instances to upgrade immediately, noting that GitLab.com has already been patched.\u200b<\/p>\n<p>The most severe vulnerability, tracked as\u00a0CVE-2025-7659\u00a0(CVSS 8.0), lies in the Web IDE. This flaw involves \u201cincomplete validation,\u201d meaning the system fails to verify who is accessing certain data properly.<\/p>\n<p>An unauthenticated attacker, someone without a username or password, could exploit this to steal access tokens and view private software repositories.\u200b<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">CVE ID<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Severity<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2025-7659<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">High (8.0)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Token Theft<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Unauthenticated access to private tokens via Web IDE.<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2025-8099<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">High (7.5)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">DoS<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Service crash via repeated GraphQL queries.<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2026-0958<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">High (7.5)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">DoS<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Resource exhaustion via JSON validation bypass.<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>CVE-2025-14560<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">High (7.3)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">XSS<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">malicious script injection in Code Flow.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>The update also resolves two dangerous <a href=\"https:\/\/cybersecuritynews.com\/denial-of-servicedos-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Denial-of-Service (DoS) issues<\/a>. In a DoS attack, a hacker tries to overwhelm a system to knock it offline.<\/p>\n<p>CVE-2025-8099\u00a0(CVSS 7.5) allows attackers to crash the service by sending repeated, complex queries to the GraphQL interface.<\/p>\n<p>CVE-2026-0958\u00a0(CVSS 7.5) exploits the JSON validation middleware, letting attackers exhaust the server\u2019s memory or CPU.\u200b<\/p>\n<p>Another major fix addresses\u00a0CVE-2025-14560\u00a0(CVSS 7.3), a <a href=\"https:\/\/cybersecuritynews.com\/cisa-openplc-scadabr-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cross-Site Scripting (XSS)<\/a> vulnerability in the \u201cCode Flow\u201d feature. XSS flaws allow attackers to inject malicious scripts into trusted websites.<\/p>\n<p>In this case, an attacker could hide code that executes when another user views it, potentially allowing them to perform actions on behalf of that victim.\u200b<\/p>\n<p><a href=\"https:\/\/about.gitlab.com\/releases\/2026\/02\/10\/patch-release-gitlab-18-8-4-released\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">GitLab strongly recommends<\/a> that all customers running affected versions upgrade to the latest patch immediately.<\/p>\n<p>While the update fixes these critical issues, it also addresses several medium-severity bugs, including Server-Side Request Forgery (SSRF) and HTML injection flaws.<\/p>\n<p>Administrators should be aware that upgrading single-node instances may require brief downtime for database migrations.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/gitlab-patches-dos-xssattacks\/\">GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/gitlab-patches-dos-xssattacks\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks A critical security update has been released for both the Community Edition (CE) and Enterprise Edition (EE) to address multiple high-severity vulnerabilities. The patches, available in versions 18.8.4, 18.7.4, and 18.6.6, fix flaws that could allow attackers to crash servers, steal data, or hijack [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,2294,2178],"tags":[130],"class_list":["post-10565","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-gitlab","category-security-updates","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10565"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10565"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10565\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10565"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10565"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10565"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}