Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

GitLab

GitLab Patch Release: 18.3.2, 18.2.6, 18.1.6

patch-release-gitlab-18-3-2-released Sep 10, 2025 Source: Vendor

Imported by the GitLab patch release catcher from https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-3-2-released/. 6 CVE sections listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-3-2-released/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

6 lines
Showing 1–6 of 6
CVE-2025-2256 BR2025-0000-009654 unclaimed
Denial of Service issue in SAML Responses impacts GitLab CE/EE
Credited as yuki_osaki
CVE-2025-6454 BR2025-0000-009655 unclaimed
Server-Side Request Forgery issue in Webhook custom header impacts GitLab CE/EE
Credited as ppee
CVE-2025-1250 BR2025-0000-009656 unclaimed
Denial of Service issue in User-Controllable Fields impacts GitLab CE/EE
Credited as pwnie
CVE-2025-7337 BR2025-0000-009657 unclaimed
Denial of Service issue in endpoint file upload impacts GitLab CE/EE
Credited as pwnie
CVE-2025-10094 BR2025-0000-009658 unclaimed
Denial of Service issue in token listing operations impacts GitLab CE/EE
Credited as pwnie
CVE-2025-6769 BR2025-0000-009659 unclaimed
Information disclosure issue in runner endpoints impacts GitLab CE/EE
Credited as iamgk808