Monday , September 7 2026
Gitlab

GitLab Releases Critical Patches for High-Severity Vulnerabilities

GitLab has released a new patch to fix security vulnerabilities and stability issues in versions 18.8.2, 18.7.2, and 18.6.4 for both Community and Enterprise Editions. These updates are ready for self-managed installations and include crucial bug fixes and security improvements. Administrators should upgrade as soon as possible.

The GitLab patch release is for Community and Enterprise Editions with affected versions. GitLab.com is already updated, and GitLab Dedicated users don’t need to do anything. However, self-managed instances should upgrade to reduce vulnerabilities.

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called...
Read More
New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

CrowdStrike launched CrowdStrike SafeMind, a set of special security models and tools from the CrowdStrike Cyber Superintelligence Lab. The SafeMind...
Read More
CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

Chinese-speaking hackers have added Claude, Qwen, and DeepSeek to their hacking system to automate cyberattacks on governments and other targets...
Read More
Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

India: C-DOT Launches 14 Local Quantum-Safe Technologies

India is making its communication systems safer and stronger by launching 14 local quantum products. These products were made by...
Read More
India: C-DOT Launches 14 Local Quantum-Safe Technologies

14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Over 14,000 Dahua security cameras connected to the internet have been hacked in a 35-day online attack that affected devices...
Read More
14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Microsoft Reveals Project Zenith Windows PCs Able to Run 30B+ AI Models Locally

Microsoft has launched Project Zenith, a new Windows 11 experience for developers. It is made for powerful PCs that can...
Read More
Microsoft Reveals Project Zenith Windows PCs Able to Run 30B+ AI Models Locally

Google issues warning of new Chrome zero-day flaw exploited

Google has updated the Chrome browser to fix a serious security issue in the V8 engine and 11 other flaws....
Read More
Google issues warning of new Chrome zero-day flaw exploited

CrowdStrike’s ‘FalconFlank’ zero-day allows SYSTEM privileges

An unnamed security expert known as "Nightmare Eclipse" shared a CrowdStrike Falcon zero-day exploit called "FalconFlank." This tool allows hackers...
Read More
CrowdStrike’s ‘FalconFlank’ zero-day allows SYSTEM privileges

727,000 data exposes: French hospital fined €500,000

France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for not properly protecting the data...
Read More
727,000 data exposes: French hospital fined €500,000

Overview of the Latest GitLab Patch Release:

This GitLab patch release fixes various security issues in both the Community and Enterprise Editions, including several high-severity vulnerabilities.

A serious issue, CVE-2025-13927, is a denial of service vulnerability in Jira Connect integration. GitLab stated that an unauthenticated attacker could cause a denial of service by sending specially crafted requests with bad authentication data. This affects all GitLab CE/EE versions from 11.9 up to, but not including, versions 18.6.4, 18.7.2, and 18.8.2. The vulnerability has a CVSS score of 7.5. GitLab acknowledged a92847865 for reporting it via their HackerOne bug bounty program.

CVE-2025-13928 is a serious issue affecting the Releases API. It allows unauthenticated users to cause a denial of service due to poor authorization validation. This vulnerability impacts GitLab Community and Enterprise Editions from version 17.7 before patches and has a CVSS score of 7.5. The same researcher reported it.

GitLab fixed CVE-2026-0723, a vulnerability in authentication services that could let attackers bypass two-factor authentication using a victim’s credential ID. It affects versions from 18.6 before the patch and has a CVSS score of 7.4. The issue was reported by ahacker1 on HackerOne.

Medium-severity issues include CVE-2025-13335, an infinite loop flaw in Wiki redirects that can lead to a denial of service by allowing authenticated users to create corrupted Wiki documents. This affects versions from 17.1 onward and has a CVSS score of 6.5. GitLab also resolved CVE-2026-1102, a denial-of-service vulnerability in an API endpoint caused by repeated bad SSH authentication requests, affecting versions from 12.3 onward with a CVSS score of 5.3. This vulnerability was found internally by team member Thiago Figueiró.

Bug Fixes and Upgrade Considerations for Self-Managed Users :

The GitLab patch release not only fixes vulnerabilities but also resolves numerous bugs in versions 18.8.2, 18.7.2, and 18.6.4. Key fixes include issues with merge request reviewer crashes, dropdown race conditions, container repository indexing, Git LFS throttling, accessibility issues, and Git push errors in self-managed setups. Improvements were also made for CI jobs, Sidekiq worker behavior, migration health checks, and AI catalog workflows.

GitLab warns that the patch release has database migrations that could affect the upgrade process. Single-node setups will face downtime during the upgrade as migrations need to complete before a restart. In contrast, multi-node setups can avoid downtime by using zero-downtime upgrade methods. Version 18.7.2 allows post-deploy migrations to run after the main upgrade.

GitLab advises all users of Community and Enterprise Edition to upgrade to the latest patch release promptly to minimize vulnerabilities and ensure stability.

Check Also

WordPress plugin

Critical WordPress Plugin Flaw Exposes 600,000 Sites to Attacks

A big security flaw in the Forminator Forms WordPress plugin might let unapproved users upload …