CVE-2025-2615: Insertion of Sensitive Information Into Sent Data in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.
Other sources
GitLab has remediated an issue that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-2615?
CVE-2025-2615 is considered a moderate severity vulnerability that allows blocked users to access sensitive information.
How do I fix CVE-2025-2615?
To remediate CVE-2025-2615, upgrade GitLab to versions 18.3.6, 18.4.4, or 18.5.2.
Which versions of GitLab are affected by CVE-2025-2615?
CVE-2025-2615 affects all GitLab CE/EE versions from 16.7 to prior to 18.3.6, and from 18.4 to prior to 18.4.4, and from 18.5 to prior to 18.5.2.
What types of vulnerabilities does CVE-2025-2615 exploit?
CVE-2025-2615 exploits the ability of blocked users to establish GraphQL subscriptions through WebSocket connections.
Is CVE-2025-2615 specific to certain GitLab editions?
CVE-2025-2615 affects both GitLab Community Edition (CE) and Enterprise Edition (EE) versions.