GitLab Patch: Fixes CI/CD Credential Theft & Unauthenticated DoS Attacks

GitLab Patch: Fixes CI/CD Credential Theft & Unauthenticated DoS Attacks GitLab has released an important security update today affecting both its Community Edition (CE) and Enterprise Edition (EE). The release addresses multiple high-severity vulnerabilities, ranging from … Read more Published Date: Nov 26, 2025 (1 hour, 33 minutes ago) Vulnerabilities has been mentioned in this article.

CVE-2025-66035 – Angular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLs

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site […]

CVE-2025-66030 – node-forge ASN.1 OID Integer Truncation

The following table lists the changes that have been made to the CVE-2025-66030 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 26, 2025 Action […]

CVE-2025-66031 – node-forge ASN.1 Unbounded Recursion

The following table lists the changes that have been made to the CVE-2025-66031 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 26, 2025 Action […]

CVE-2025-64335 – Suricata is vulnerable to a null deref when used with base64_data

The following table lists the changes that have been made to the CVE-2025-64335 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 26, 2025 Action […]

CVE-2025-64334 – Suricata is vulnerable to unbounded memory growth for decompression

The following table lists the changes that have been made to the CVE-2025-64334 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 26, 2025 Action […]

CVE-2025-64333 – Suricata is vulnerable to a stack overflow from big content-type

The following table lists the changes that have been made to the CVE-2025-64333 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 26, 2025 Action […]

CVE-2025-64332 – Suricata is vulnerable to a stack overflow on larger compressed data

The following table lists the changes that have been made to the CVE-2025-64332 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 26, 2025 Action […]

CVE-2025-64331 – Suricata is vulnerable to a stack overflow on large file transfers with http-body-printable

The following table lists the changes that have been made to the CVE-2025-64331 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 26, 2025 Action […]