CVE-2025-11990
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to gain CSRF tokens by exploiting improper input validation in repository references combined with redirect handling weaknesses.
Scoring
- Severity
- LOW
- CVSS base score
- 3.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS probability
- 0.30%
- CWE
- CWE-177
- Published
- 2025-11-15
- Last modified
- 2026-03-12
Affected products
- GitLab GitLab
- GitLab GitLab
Weakness type
Related vulnerabilities
- CVE-2026-76172 — fast-uri vulnerable to host confusion via percent-encoded scheme normalization
- CVE-2026-67448 — Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
- CVE-2026-15371 — Velociraptor Stored XSS in URL column types
- CVE-2026-59083 — Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
- CVE-2026-41041 — Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints.
- CVE-2026-6414 — @fastify/static vulnerable to route guard bypass via encoded path separators
- CVE-2026-29045 — Hono: Arbitrary file access via serveStatic vulnerability
- CVE-2026-22037 — @fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)