GitLab released security updates 17.10.1, 17.9.3, and 17.8.6 for Community Edition and Enterprise Edition to fix multiple vulnerabilities affecting self-managed deployments. The company said GitLab.com had already been patched and GitLab Dedicated customers did not need to take action, but urged self-managed administrators to upgrade immediately because the release addressed several high- and medium-severity issues across the platform.
The patched set includes two high-severity cross-site scripting flaws, a high-severity privilege persistence issue, and additional access control, resource consumption, and command injection weaknesses. GitLab linked the fixes to CVE-2025-2255, CVE-2025-0811, CVE-2025-2242, CVE-2024-12619, CVE-2024-10307, and CVE-2024-9773, and also disclosed a prompt injection issue in the Amazon Q integration that was still awaiting CVE assignment at the time of the release.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
On March 26, 2025, GitLab released versions 17.10.1, 17.9.3, and 17.8.6 for Community Edition and Enterprise Edition and urged self-managed customers to upgrade immediately. The patches addressed multiple issues, including CVE-2025-2255, CVE-2025-0811, CVE-2025-2242, CVE-2024-12619, CVE-2024-10307, and CVE-2024-9773, while GitLab.com had already been patched.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
docs.gitlab.com
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.