Medium severity4.3NVD Advisory· Published Jul 10, 2025· Updated Jun 17, 2026
CVE-2025-3396
CVE-2025-3396
Description
An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass group-level forking restrictions by manipulating API requests.
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 13.3
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.3.0,<17.11.6
- Range: 13.3 <= v < 17.11.6, 18.0 <= v < 18.0.4, 18.1 <= v < 18.1.2
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/534636nvdBroken Link
- hackerone.com/reports/3079956nvdPermissions Required
News mentions
1- GitLab Patch Release: 18.1.2, 18.0.4, 17.11.6GitLab Security Releases · Jul 9, 2025