CVE-2025-4439: Cross-site scripting issue impacts Kubernetes Proxy in GitLab CE/EE using CDNs
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4439?
CVE-2025-4439 has been assigned a medium severity rating due to potential cross-site scripting vulnerabilities.
How do I fix CVE-2025-4439?
To fix CVE-2025-4439, upgrade GitLab CE/EE to version 18.0.5, 18.1.3, or 18.2.1 or later.
Who is affected by CVE-2025-4439?
CVE-2025-4439 affects all versions of GitLab CE/EE from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1.
What kind of vulnerability is CVE-2025-4439?
CVE-2025-4439 is a cross-site scripting vulnerability that can be exploited by authenticated users.
When was CVE-2025-4439 discovered?
CVE-2025-4439 was discovered recently, affecting multiple versions of GitLab CE/EE.