CVE-2025-11990: Improper Handling of URL Encoding (Hex Encoding) in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to gain CSRF tokens by exploiting improper input validation in repository references combined with redirect handling weaknesses.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to gain CSRF tokens by exploiting improper input validation in repository references combined with redirect handling weaknesses.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11990?
CVE-2025-11990 has been classified as a moderate severity vulnerability.
How do I fix CVE-2025-11990?
To fix CVE-2025-11990, update GitLab EE to version 18.4.4 or 18.5.2 or later.
What versions of GitLab EE are affected by CVE-2025-11990?
CVE-2025-11990 affects GitLab EE versions from 18.4 before 18.4.4 and 18.5 before 18.5.2.
Can CVE-2025-11990 be exploited by unauthenticated users?
No, CVE-2025-11990 requires an authenticated user to exploit the vulnerability.
What is the nature of the issue in CVE-2025-11990?
CVE-2025-11990 involves improper input validation in repository references and weaknesses in redirect handling.