Junglewise Threat Intelligence

CVE-2025-9484: GitLab Enterprise Edition information disclosure in GraphQL API

CVE-2025-9484 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Technologies: GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab has fixed a security flaw in its Enterprise Edition that could allow a logged-in user to view the email addresses of other users. This issue occurs when specific queries are made through the platform's data interface. While it does not allow for full account takeover, it results in the unauthorized exposure of private contact information.

Technical details

A missing authorization vulnerability (CWE-862) exists in GitLab Enterprise Edition (EE) within its GraphQL API implementation. An authenticated attacker can craft specific GraphQL queries to bypass intended privacy restrictions and retrieve the email addresses of other users on the instance. The vulnerability affects versions 16.6 through 18.10.3 (specific patch ranges apply). The issue is remediated in versions 18.8.9, 18.9.5, and 18.10.3. Exploitation requires network access and valid user credentials but no administrative privileges or user interaction.

Affected products

  • GitLab GitLab Enterprise Edition 16.6 to <18.8.9, 18.9 to <18.9.5, 18.10 to <18.10.3

Timeline

  • 2026-04-08: patched: GitLab released versions 18.10.3, 18.9.5, and 18.8.9 to address the issue.
  • 2026-04-08: disclosed

References

Related threats