GitLab Releases Patch Versions 18.4.1, 18.3.3, 18.2.7 with Security Fixes

This title was summarized by AI from the post below.

🚨 GitLab Patch Releases: 18.4.1, 18.3.3, 18.2.7 Are Now Available 📅 Release Date: September 25, 2025 🛡️ Type: Security & Bug Fixes 📦 Applies to: GitLab Community Edition (CE) & Enterprise Edition (EE) GitLab has released three patch versions with critical security and stability improvements. These updates address multiple vulnerabilities, including: 🔐 High-Severity Security Fixes: CVE-2025-9642: XSS via Script Gadgets (CVSS 8.7) CVE-2025-10858: DoS via malicious JSON files (CVSS 7.5) CVE-2025-8014: Bypass of GraphQL query limits (CVSS 7.5) 🧵 Other notable vulnerabilities fixed: Information disclosure in virtual registry configs Privilege escalation from Developer role DoS via GraphQL blobSearch & string conversion methods Improper authorization and project ownership reassignment 📝 Bug Fixes Across All Versions: These releases also include dozens of backported fixes improving performance, user experience, and internal stability across GitLab CE/EE. 📌 Important Notes: No new DB migrations GitLab.com is already patched All self-managed instances should upgrade immediately GitLab Dedicated customers do not need to take action 🔄 Recommended Action: Upgrade your instance to 18.4.1, 18.3.3, or 18.2.7 depending on your version stream. 📖 Full release notes → GitLab Patch Blog 🔒 Read best practices → Securing GitLab Instances Source Link : https://lnkd.in/e_GmpN9J #GitLab #SecurityUpdate #CVE #DevSecOps #ApplicationSecurity #PatchNow #OpenSourceSecurity #BugFixes #GitLabEE #GitLabCE

To view or add a comment, sign in

Explore content categories