Security Update: GitLab Addresses XSS, DoS, and Account Takeover Exploits

Security Update: GitLab Addresses XSS, DoS, and Account Takeover Exploits

GitLab Issues Critical Security Updates Addressing Major Vulnerabilities

GitLab has released critical security patches to address multiple high-severity vulnerabilities across its platform, reinforcing its security posture amid the rising tide of cyber threats.

Patch versions 17.11.1, 17.10.5, and 17.9.7 are now available for both the Community Edition (CE) and Enterprise Edition (EE).

These updates fix significant issues — including cross-site scripting (XSS), denial-of-service (DoS) attacks, and account takeover vulnerabilities — while also delivering a comprehensive set of bug fixes to enhance stability and performance.


Major Vulnerabilities Addressed

The security patches remediate several critical flaws that posed substantial risks to GitLab deployments:

  • Cross-Site Scripting (XSS) Vulnerabilities:
    Two critical XSS flaws were patched in the Maven Dependency Proxy:
    • CVE-2025-1763 (CVSS 8.7): Allowed attackers to bypass content security policies.
    • CVE-2025-2443: A similar XSS issue caused by misconfigured cache headers.
  • Network Error Logging (NEL) Header Injection:
    CVE-2025-1908 (CVSS 7.7) — An issue that could enable threat actors to monitor browser activity and facilitate account takeovers.
  • Denial-of-Service (DoS) Vulnerability:
    CVE-2025-0639 (CVSS 6.5) — A medium-severity DoS bug affecting the issue preview functionality.
  • Access Control Flaw:
    CVE-2024-12244 (CVSS 4.3) — An issue allowing unauthorized users to view branch names even when repository assets were disabled.

Key Bug Fixes in This Release

Beyond security patches, GitLab’s latest updates include several important bug fixes:

Version 17.11.1

  • Pipeline Security: allow_composite_identities_to_run_pipelines feature flag introduced.
  • Amazon Q Integration: Addressed disconnects and documentation issues.
  • CI/CD Enhancements: Improved handling of CI Inputs and Static Reachability templates.
  • Cloud Connector: Tokens now synchronize hourly for greater reliability.
  • Workhorse & Gitaly: Dependency updates for better stability.
  • UI Improvements: Fixed file attachment issues in the new interface.

Version 17.10.5

  • Mailroom Location: Fixed UBI mailroom path problems.
  • gRPC Library: Upgraded to v1.71.1 for security improvements.
  • Zoekt Indexing: Fixed project filtering, node management, and instant eviction issues.
  • Session Security: Session cookies now clear on browser closure.
  • AI Event Backfilling: Enhanced data migration from PostgreSQL to ClickHouse.
  • Cloud Connector: Hourly token sync fix backported.

Version 17.9.7

  • FIPS & UBI Compliance: Pipeline naming fixes backported.
  • Encryption Key Management: Introduced gitlab:doctor:encryption_keys task.
  • Workhorse & Gitaly: Dependency upgrades for improved reliability.
  • Mailroom Path Fix: Backported UBI-related fixes.
  • gRPC Update: Security upgrade to v1.71.1.

As cyberattacks grow more sophisticated, GitLab remains committed to proactive security measures, transparent communication, and timely patch releases.

Security experts strongly urge all organizations to upgrade immediately to minimize exposure to these known vulnerabilities.

This update also highlights the collaborative strength of the open-source community, with many vulnerabilities reported through GitLab’s HackerOne bug bounty program.

In an increasingly complex threat environment, organizations are encouraged to follow cybersecurity best practices — including regular system audits and immediate application of security updates — to safeguard their services and data.

More Articles & Posts