CVE-2025-11224

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to execute stored cross-site scripting through improper input validation in the Kubernetes proxy functionality.
Configurations

No configuration.

History

14 Jan 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 19:16

Updated : 2026-01-16 15:55


NVD link : CVE-2025-11224

Mitre link : CVE-2025-11224

CVE.ORG link : CVE-2025-11224


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')