GitLab released security updates addressing a high-severity runner hijacking vulnerability (CVE-2025-11702) and multiple denial-of-service (DoS) vulnerabilities affecting both GitLab Community Edition (CE) and Enterprise Edition (EE). The vulnerabilities impact versions prior to 18.5.1, 18.4.3, and 18.3.5, and could allow attackers to compromise CI/CD runners or disrupt GitLab services. Administrators are urged to apply the latest patches to mitigate these risks and ensure the security of their GitLab environments.
The runner hijacking flaw could enable unauthorized access or control over GitLab runners, posing a significant threat to organizations relying on automated pipelines. The coordinated disclosure and patch release highlight the importance of timely updates, as exploitation of these vulnerabilities could lead to service outages or further compromise within affected environments.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
GitLab issued security updates addressing the high-severity runner hijacking vulnerability CVE-2025-11702 along with multiple denial-of-service vulnerabilities. The fixes were publicly reflected in security reporting and an official advisory on October 22, 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.