CVE-2025-13978: Generation of Error Message Containing Sensitive Information in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to discover the names of private projects they do not have access through API requests.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to discover the names of private projects they do not have access through API requests.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-13978?
CVE-2025-13978 is classified as a medium severity vulnerability.
How does CVE-2025-13978 affect GitLab users?
CVE-2025-13978 allows authenticated users to discover names of private projects they do not have access to through API requests.
How do I fix CVE-2025-13978?
To remediate CVE-2025-13978, users should upgrade to GitLab versions 18.6.2 or later.
What versions of GitLab are affected by CVE-2025-13978?
CVE-2025-13978 affects GitLab versions between 17.5 and 18.6.2 inclusive.
Is there an official patch for CVE-2025-13978?
Yes, GitLab has released patches in version 18.6.2 to address CVE-2025-13978.