VDB
CVE-2025-12653
CVE-2025-12653
PUBLISHED
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific conditions could have allowed an unauthenticated user to join arbitrary organizations by changing headers on some requests.
EPSS 0.06% · 19.3th percentile
Risk Scores
EPSS Score
0.06%
19.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 18.3.0, 18.5.0, 18.6.0 |
| Bitnami | gitlab | 18.5.0, 18.6.0, 18.3.0 |
Timeline
- Jan 21, 1970 Security Advisory
- Nov 3, 2025 CVE ID Reserved
- Nov 26, 2025 Coalition ESS Score
- Nov 26, 2025 CVE Published
- Nov 26, 2025 PoC Published
- Nov 27, 2025 EPSS Score
- Nov 27, 2025 PoC Published
- Nov 29, 2025 PoC Published
- Dec 1, 2025 Coalition ESS Score
- Dec 2, 2025 EPSS Score
- Dec 4, 2025 Coalition ESS Score
- Dec 6, 2025 EPSS Score