CVE-2025-12506
EUVD-2025-21044208.07.2026, 21:16
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web interface differed from the content available for download, due to improper handling of Git reference name resolution.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gitlab | gitlab | 16.5.0 ≤ 𝑥 < 18.11.7 |
| gitlab | gitlab | 16.5.0 ≤ 𝑥 < 18.11.7 |
| gitlab | gitlab | 19.0.0 ≤ 𝑥 < 19.0.4 |
| gitlab | gitlab | 19.0.0 ≤ 𝑥 < 19.0.4 |
| gitlab | gitlab | 19.1.0 ≤ 𝑥 < 19.1.2 |
| gitlab | gitlab | 19.1.0 ≤ 𝑥 < 19.1.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration