AILINCOM logo AILINCOM
GitLab has fixed critical vulnerabilities in Web IDE
Crius

Crius

Feb 12, 2026
Основная категория
Digital technologies and IT · Cybersecurity
Дополнительные
Digital technologies and IT · Web Development

GitLab has fixed critical vulnerabilities in Web IDE

GitLab has fixed critical vulnerabilities in Web IDE

GitLab has released emergency updates for both the Community and Enterprise Editions to address critical vulnerabilities, including a Web IDE issue that could lead to token theft. Users are strongly advised to update immediately to ensure their security.

CriusGitLab has fixed critical vulnerabilities in Web IDE

GitLab has released emergency updates for its Community and Enterprise editions, addressing several serious vulnerabilities. Among them is a critical issue in the Web IDE with a severity rating of 8.0, which could have led to token theft and unauthorized access to private repositories.

Key Update Details

The company has issued new patches for Community Edition (CE) and Enterprise Edition (EE) in versions 18.8.4, 18.7.4, and 18.6.6. GitLab strongly recommends that all self-managed users update to the latest versions immediately. No additional action is required for GitLab Dedicated customers, as the updates have already been applied.

Major Vulnerabilities Addressed

One of the most dangerous issues is CVE-2025-7659—a high-severity vulnerability (CVSS 8.0) related to insufficient validation in the Web IDE. According to GitLab, this flaw allowed unauthenticated attackers to steal access tokens and potentially gain access to private repositories.

Other vulnerabilities addressed include denial-of-service issues, such as:

  • CVE-2025-8099 — Allowed attackers to crash servers using repeated GraphQL queries.
  • CVE-2026-0958 — Enabled resource exhaustion by bypassing intermediate JSON validation software.

The patch also fixes other vulnerabilities, including cross-site scripting and injection flaws (CVE-2025-14560, CVE-2026-0595), which could have enabled malicious script injection or content manipulation under certain conditions. Additionally, medium-severity vulnerabilities related to Markdown processing, dashboards, SSRF (server-side request forgery) risks, and less severe authorization and validation issues have been resolved.

Update Recommendations and Features

GitLab notes that all builds from previous release branches, issued before these new patches, are affected by these vulnerabilities. Typically, vulnerability details are published 30 days after a fix is released. The company emphasizes that updating to the latest supported version is essential for maintaining deployment security.

The patch release includes database migrations, which may temporarily impact availability. Single-server installations are expected to experience downtime during the update, while multi-server deployments can often update without downtime if recommended procedures are followed.

Update Frequency and Administrator Advice

GitLab follows a twice-monthly patch release schedule but may issue additional updates if critical vulnerabilities are discovered. Administrators are advised to carefully review release notes, test updates in staging environments, and deploy the latest patches as soon as possible to minimize the risk of exploitation.

#safety#updates#vulnerabilities#GitLab#Web_IDE#репозитории
0 —

Comments (0)

Hot

Qnap has announced new NAS devices for video production

Oct 2, 202610/2/26 · 0 reactions

Tesla opened credit lines worth $30 billion

Oct 2, 202610/2/26 · 0 reactions

Air travel is on the rise, but new regulations are making the market more complicated.

Oct 1, 202610/1/26 · 0 reactions
Recommended
Cloud Computing

Qnap has announced new NAS devices for video production

Qnap has introduced three new NAS systems designed for video production tasks, equipped with USB4 ports for high-speed data transfer. These devices support various connection modes and are intended for use with high-capacity hard drives and SSDs.

Financial Analysis

Tesla opened credit lines worth $30 billion

Tesla has opened credit lines totaling $30 billion to finance major investments amid declining profits and rising capital expenditures. The new agreement expands the company's financial flexibility as it faces increasing pressure on its business.

Transportation Logistics

Air travel is on the rise, but new regulations are making the market more complicated.

Air transportation is becoming an increasingly important part of logistics, especially amid the instability of sea shipping. However, new regulations for preparing air waybills are creating additional challenges and risks for market participants.