GPU VulnDB

Database/Control plane, storage & DevOps

GitLab: crafted Git ref names make the web UI show different content than the downloaded archive

CVSS 4.3CVE-2025-12506Control plane, storage & DevOpscurated

Impact

Improper handling of Git reference name resolution let an authenticated user create a repository whose content as rendered in the GitLab web interface differs from the content served for download. That is a review-integrity problem rather than a code-execution one: a reviewer approving what the UI shows is not approving what a CI runner or a build job actually fetches. For a GPU fleet whose container images, Dockerfiles, CUDA build recipes and Kubernetes manifests flow through GitLab, it means a change that looks clean in the merge request can ship different bytes into an image that later runs on every node. Confidentiality and availability are unaffected; the impact is integrity of what gets built and deployed.

Who can reach it

Any authenticated GitLab user who can create a repository or push refs to one. No admin rights needed; exploitation depends on someone reviewing or consuming the affected repository.

What to do

Upgrade GitLab CE/EE to 18.11.7, 19.0.4 or 19.1.2 (affected: 16.5 up to those releases) and restart the GitLab services - for Omnibus a gitlab-ctl reconfigure/restart, for the Helm chart a rolling restart of the web and Gitaly pods. No node reboot and no downtime for GPU workloads. Worth pairing with a check of recently merged changes in any repository that feeds image builds, since the fix does not tell you whether the divergence was ever used.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.