CVE-2025-3950: Exposure of Private Personal Information to an Unauthorized Actor in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.
Other sources
GitLab has remediated an issue that could have allowed a user to leak sensitive connection information by referencing specially crafted images that bypass asset proxy protection.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-3950?
CVE-2025-3950 has a severity rating that indicates a moderate risk due to the potential for sensitive information leakage.
How do I fix CVE-2025-3950?
To remediate CVE-2025-3950, users should upgrade to GitLab version 18.7.1 or later.
Who is affected by CVE-2025-3950?
CVE-2025-3950 affects GitLab versions from 10.3 up to 18.5.5, 18.6.3, and 18.7.1.
What kind of sensitive information can CVE-2025-3950 expose?
CVE-2025-3950 can potentially expose sensitive connection information by referencing specially crafted images.
What does the asset proxy protection do in GitLab?
The asset proxy protection in GitLab is designed to prevent unauthorized access to sensitive assets, which CVE-2025-3950 could bypass.