HIGH
Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab
Published Dec 5, 2025
7.7
HIGHCVSS 3.1
EPSS 0.25%
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context under specific conditions.
Affected products
-
- Version 18.4StatusaffectedConstraints<18.4.5
- Version 18.5StatusaffectedConstraints<18.5.3
- Version 18.6StatusaffectedConstraints<18.6.1
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 18.4.5, 18.5.3, 18.6.1 or above.
Weaknesses (1)
References (3)
- https://about.gitlab.com/releases/2025/11/26/patch-release-gitlab-18-6-1-released/ vendor-advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/494478 issue-trackingpermissions-requiredBroken Link
- https://hackerone.com/reports/2707421 technical-descriptionexploitpermissions-requiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://about.gitlab.com/releases/2025/11/26/patch-release-gitlab-18-6-1-released/ | vendor-advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/494478 | issue-trackingpermissions-requiredBroken Link | |
| https://hackerone.com/reports/2707421 | technical-descriptionexploitpermissions-requiredThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Dec 5, 2025
Updated Feb 26, 2026
Reserved Sep 25, 2024
Link CVE-2024-9183
CISA Vulnrichment
Updated Dec 9, 2025