CVE-2025-9484 is an information disclosure vulnerability in GitLab Enterprise Edition that allows authenticated users to access other users' email addresses through specific GraphQL queries. The vulnerability affects multiple versions across three release branches: 16.6 through 18.8.8, 18.9 through 18.9.4, and 18.10 through 18.10.2, with patches available in versions 18.8.9, 18.9.5, and 18.10.3 respectively. The vulnerability carries a CVSS score of 4.3 (Medium severity) with a network-based attack vector requiring low complexity and valid user credentials, but no user interaction. The impact is limited to confidentiality; integrity and availability are not affected. The EPSS score of 0.00014 indicates very low probability of exploitation relative to other CVEs, and the vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog. There is no evidence of active exploitation in the wild. No public exploit code has been identified, and community attention remains minimal based on the inactive status and low engagement metrics. Organizations using affected GitLab EE versions should prioritize patching as a routine maintenance task rather than an urgent security response.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.6.0, < 18.8.9CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 18.9.0, < 18.9.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 18.10.0, < 18.10.3CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 18.10, < 18.10.3CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 16.6, < 18.8.9CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.