PT-2026-3935 · Gitlab · Gitlab Ce/Ee

Published

2026-01-21

·

Updated

2026-02-19

·

CVE-2025-13928

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 17.7 through 18.6.3 GitLab CE/EE versions 18.7 through 18.7.1 GitLab CE/EE versions 18.8 through 18.8.1
Description An issue in GitLab CE/EE allows an unauthenticated user to cause a denial of service condition by exploiting incorrect authorization validation in API endpoints. The issue affects API endpoints where authorization checks were not properly implemented, potentially allowing unauthorized access.
Recommendations GitLab CE/EE versions 17.7 through 18.6.3 should be updated to version 18.6.4 or later. GitLab CE/EE versions 18.7 through 18.7.1 should be updated to version 18.7.2 or later. GitLab CE/EE versions 18.8 through 18.8.1 should be updated to version 18.8.2 or later.

Exploit

Fix

DoS

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2026-00979
BIT-GITLAB-2025-13928
CVE-2025-13928

Affected Products

Gitlab Ce/Ee