PT-2025-43136 · Gitlab · Gitlab

Published

2025-10-22

·

Updated

2025-11-06

·

CVE-2025-11702

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab versions 3.8 through 8.5
Description Multiple vulnerabilities exist in GitLab, including improper access control, denial of service, and incorrect authorization. These issues impact the runner API. A search on Netlas.io using the provided dork and favicon hash may identify potentially affected instances.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-13579
BIT-GITLAB-2025-11702
CVE-2025-11702

Affected Products

Gitlab