SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2025-12506

LOW · CVSS 3.5 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

GitLab versions prior to 18.11.7, 19.0.4, and 19.1.2 are vulnerable to a flaw that allows authenticated users to create repositories with discrepancies between the web interface content and downloadable content, stemming from improper Git reference name resolution. While the severity is rated low, organizations using affected versions should prioritize remediation to prevent potential data integrity issues. Users and administrators of GitLab CE/EE should apply the necessary updates to mitigate this risk.

CVE
CVE-2025-12506
Severity
LOW
CVSS
3.5
EPSS
0.19%
GitLab

Original NVD Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web interface differed from the content available for download, due to improper handling of Git reference name resolution.

Related CVEs

Other vulnerabilities affecting the same vendor(s)