Severity
5.3MEDIUMNVD
EPSS
0.0%
top 95.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13
Latest updateNov 5

Description

An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCable potentially allowed revoked Personal Access Tokens access to streaming results.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages11 packages

CVEListV5gitlab/gitlab16.1117.6.5+2
NVDgitlab/gitlab16.11.017.6.5+2
debiandebian/gitlab< gitlab 17.6.5-1 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-x774-v4vm-3h8m: An issue discovered in GitLab CE/EE affecting all versions from 162025-02-13
OSV
CVE-2025-1198: An issue discovered in GitLab CE/EE affecting all versions from 162025-02-13

📋Vendor Advisories

5
Red Hat
vim: Vim vulnerable to potential data loss with zip.vim and special crafted zip files2025-03-13
GitLab
CVE-2025-1198: An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-2025-02-13
Red Hat
kernel: vsock/bpf: return early if transport is not assigned2025-01-31
Debian
CVE-2025-1198: gitlab - An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 1...2025
Microsoft
A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to crash linux kernel by simulating ax25 device using 6pack driver from user space.2022-08-09

📄Research Papers

2
arXiv
Security Analysis of Agentic AI Communication Protocols: A Comparative Evaluation2025-11-05
arXiv
Improving Google A2A Protocol: Protecting Sensitive Data and Mitigating Unintended Harms in Multi-Agent Systems2025-08-28