VDB

CVE-2025-12653

CVE-2025-12653 PUBLISHED

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific conditions could have allowed an unauthenticated user to join arbitrary organizations by changing headers on some requests.

EPSS 0.06% · 19.3th percentile

Risk Scores

EPSS Score
0.06%
19.3th percentile

Affected Products

VendorProductVersions
Bitnamigitlab18.3.0, 18.5.0, 18.6.0
Bitnamigitlab18.5.0, 18.6.0, 18.3.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Nov 3, 2025 CVE ID Reserved
  • Nov 26, 2025 Coalition ESS Score
  • Nov 26, 2025 CVE Published
  • Nov 26, 2025 PoC Published
  • Nov 27, 2025 EPSS Score
  • Nov 27, 2025 PoC Published
  • Nov 29, 2025 PoC Published
  • Dec 1, 2025 Coalition ESS Score
  • Dec 2, 2025 EPSS Score
  • Dec 4, 2025 Coalition ESS Score
  • Dec 6, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›