VDB

CVE-2025-6601

CVE-2025-6601 PUBLISHED

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.

EPSS 0.02% · 5.4th percentile

Risk Scores

EPSS Score
0.02%
5.4th percentile

Affected Products

VendorProductVersions
Bitnamigitlab18.4.0, 18.5.0
Bitnamigitlab18.4.0, 18.5.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Oct 22, 2025 CVE Published
  • Oct 27, 2025 EPSS Score
  • Oct 27, 2025 Coalition ESS Score
  • Nov 1, 2025 Coalition ESS Score
  • Nov 2, 2025 EPSS Score
  • Nov 7, 2025 EPSS Score
  • Nov 8, 2025 Coalition ESS Score
  • Nov 13, 2025 EPSS Score
  • Nov 16, 2025 Coalition ESS Score
  • Nov 17, 2025 Coalition ESS Score
  • Nov 19, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›