gitlab-rails-ce-18.1
Chainguard
Status
Impact
GitLab CE 18.1.5 uses nokogiri 1.18.8, which is vulnerable to GHSA-353f-x4gh-cqq8 (multiple libxml2 CVEs including CVE-2025-6021, CVE-2025-6170, CVE-2025-49794, CVE-2025-49795, CVE-2025-49796). Fixed version: 1.18.9. Deferring to upstream GitLab to address this CVE in a subsequent update. See: https://docs.gitlab.com/ee/development/dependencies.html.
Status