Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

INFO

Published Date :

2026-01-09T10:04:51.264Z

Last Modified :

2026-01-09T14:42:21.828Z

Source :

GitLab
AFFECTED PRODUCTS

The following products are affected by CVE-2025-3950 vulnerability.

Vendors Products
Gitlab
  • Gitlab
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-3950.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact