Vulnerability Database

308,485

Total vulnerabilities in the database

CVE-2025-11990

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to gain CSRF tokens by exploiting improper input validation in repository references combined with redirect handling weaknesses.

  • Published: Nov 15, 2025
  • Updated: Nov 16, 2025
  • CVE: CVE-2025-11990
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 3.1
  • AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

CWEs: