<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T10:10:09.716099+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-gitlab-2025-4979</id>
    <title>BIT-gitlab-2025-4979 — Insufficient Granularity of Access Control in GitLab</title>
    <updated>2026-10-04T10:10:09.728224+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: gitlab</p>
<p>An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-gitlab-2025-4979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0437</id>
    <title>certfr-2025-avi-0437 — De multiples vulnérabilités ont été découvertes dans GitLab. Elles permettent à un attaquant de provoquer un déni de se…</title>
    <updated>2026-10-04T10:10:09.728273+00:00</updated>
    <content>certfr-2025-avi-0437</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0437"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-240848</id>
    <title>EUVD-2026-240848</title>
    <updated>2026-10-04T10:10:09.728293+00:00</updated>
    <content>EUVD-2026-240848</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-240848"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-4979</id>
    <title>fkie_cve-2025-4979</title>
    <updated>2026-10-04T10:10:09.728306+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-4979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9vrq-hh79-6v9m</id>
    <title>GHSA-9vrq-hh79-6v9m</title>
    <updated>2026-10-04T10:10:09.728327+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9vrq-hh79-6v9m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4979</id>
    <title>UBUNTU-CVE-2025-4979</title>
    <updated>2026-10-04T10:10:09.728341+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: gitlab</p>
<p>An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1117</id>
    <title>WID-SEC-W-2025-1117 — GitLab: Mehrere Schwachstellen</title>
    <updated>2026-10-04T10:10:09.728359+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service auszulösen oder Informationen auszuspähen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1117"/>
  </entry>
</feed>
