CVE-2025-7000Sensitive Info Insertion into Sent Data in Gitlab

Severity
4.3MEDIUMNVD
EPSS
0.0%
top 99.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15
Latest updateMar 10

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages6 packages

CVEListV5gitlab/gitlab17.618.3.6+2
NVDgitlab/gitlab17.6.018.3.6+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2025-7000: An issue has been discovered in GitLab CE/EE affecting all versions from 172025-11-15
GHSA
GHSA-mfcp-rjv7-385m: An issue has been discovered in GitLab CE/EE affecting all versions from 172025-11-15

📋Vendor Advisories

6
Chrome
Stable Channel Update for Desktop: CVE-2026-39252026-03-10
GitLab
CVE-2025-7000: An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under2025-11-15
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2025-21372025-03-18
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2025-04472025-01-17
Chrome
Stable Channel Update for Desktop: CVE-2025-04342025-01-14