CVE-2025-2469: GitLab

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users.

Affected products

  • GitLab GitLab: from 17.9.0, before 17.9.6 (fixed in 17.9.6); from 17.10.0, before 17.10.4 (fixed in 17.10.4)

Published 2025-04-10. Last modified 2026-06-17.