apk package
chainguard/gitlab-workhorse-ce-18.2
pkg:apk/chainguard/gitlab-workhorse-ce-18.2
Vulnerabilities (34)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-7449 | — | < 18.2.8-r3 | 18.2.8-r3 | Nov 26, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user with specific permissions to cause a denial of service condition through HTTP response processing | ||
| CVE-2025-12571 | — | < 18.2.8-r3 | 18.2.8-r3 | Nov 26, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an unauthenticated user to cause a Denial of Service condition by sending specifically crafted requests containing ma | ||
| CVE-2025-13611 | — | < 18.2.8-r3 | 18.2.8-r3 | Nov 26, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific conditions. | ||
| CVE-2025-47914 | — | < 18.2.8-r2 | 18.2.8-r2 | Nov 19, 2025 | SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read. | ||
| CVE-2025-58181 | — | < 18.2.8-r2 | 18.2.8-r2 | Nov 19, 2025 | SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption. | ||
| CVE-2025-12983 | — | < 18.2.8-r2 | 18.2.8-r2 | Nov 15, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content with | ||
| CVE-2025-2615 | — | < 18.2.8-r2 | 18.2.8-r2 | Nov 15, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections. | ||
| CVE-2025-6171 | — | < 18.2.8-r3 | 18.2.8-r3 | Nov 15, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker with reporter access to view branch names and pipeline details by accessing the packages API | ||
| CVE-2025-7000 | — | < 18.2.8-r3 | 18.2.8-r3 | Nov 15, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with rel | ||
| CVE-2025-7736 | — | < 18.2.8-r2 | 18.2.8-r2 | Nov 15, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for projec | ||
| CVE-2025-58187 | — | < 18.2.8-r1 | 18.2.8-r1 | Oct 29, 2025 | Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains. | ||
| CVE-2025-10497 | — | < 18.2.8-r3 | 18.2.8-r3 | Oct 27, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads. | ||
| CVE-2025-11974 | — | < 18.2.8-r3 | 18.2.8-r3 | Oct 27, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints | ||
| CVE-2025-11447 | — | < 18.2.8-r3 | 18.2.8-r3 | Oct 27, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending GraphQL requests with crafted JSON paylo |
- CVE-2025-7449Nov 26, 2025affected < 18.2.8-r3fixed 18.2.8-r3
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user with specific permissions to cause a denial of service condition through HTTP response processing
- CVE-2025-12571Nov 26, 2025affected < 18.2.8-r3fixed 18.2.8-r3
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an unauthenticated user to cause a Denial of Service condition by sending specifically crafted requests containing ma
- CVE-2025-13611Nov 26, 2025affected < 18.2.8-r3fixed 18.2.8-r3
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific conditions.
- CVE-2025-47914Nov 19, 2025affected < 18.2.8-r2fixed 18.2.8-r2
SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
- CVE-2025-58181Nov 19, 2025affected < 18.2.8-r2fixed 18.2.8-r2
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
- CVE-2025-12983Nov 15, 2025affected < 18.2.8-r2fixed 18.2.8-r2
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content with
- CVE-2025-2615Nov 15, 2025affected < 18.2.8-r2fixed 18.2.8-r2
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.
- CVE-2025-6171Nov 15, 2025affected < 18.2.8-r3fixed 18.2.8-r3
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker with reporter access to view branch names and pipeline details by accessing the packages API
- CVE-2025-7000Nov 15, 2025affected < 18.2.8-r3fixed 18.2.8-r3
An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with rel
- CVE-2025-7736Nov 15, 2025affected < 18.2.8-r2fixed 18.2.8-r2
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for projec
- CVE-2025-58187Oct 29, 2025affected < 18.2.8-r1fixed 18.2.8-r1
Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.
- CVE-2025-10497Oct 27, 2025affected < 18.2.8-r3fixed 18.2.8-r3
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.
- CVE-2025-11974Oct 27, 2025affected < 18.2.8-r3fixed 18.2.8-r3
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints
- CVE-2025-11447Oct 27, 2025affected < 18.2.8-r3fixed 18.2.8-r3
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending GraphQL requests with crafted JSON paylo
Page 2 of 2