CVE-2025-12073: Server-Side Request Forgery (SSRF) in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an authenticated user to perform server-side request forgery against internal services by bypassing protections in the Git repository import functionality.
Other sources
GitLab has remediated an issue that, under certain conditions, could have allowed an authenticated user to perform server-side request forgery against internal services by bypassing protections in the Git repository import functionality.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-12073?
CVE-2025-12073 has a moderate severity rating, which indicates a potential risk to the affected systems.
How do I fix CVE-2025-12073?
To fix CVE-2025-12073, upgrade GitLab to version 18.6.6, 18.7.4, or 18.8.4 as applicable.
Which versions of GitLab are affected by CVE-2025-12073?
CVE-2025-12073 affects GitLab CE/EE versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4.
Can an unauthenticated user exploit CVE-2025-12073?
No, CVE-2025-12073 requires authentication for exploitation.
What kind of vulnerability is CVE-2025-12073?
CVE-2025-12073 is classified as a Server-Side Request Forgery (SSRF) vulnerability.