MEDIUM

CVE-2025-0993

Gitlab GitLab 2025-05-22 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.

Summary dbcve.org

GitLab CE/EE versions prior to 17.10.7, 17.11 prior to 17.11.3, and 18.0 prior to 18.0.1 contain a vulnerability where an authenticated attacker can trigger excessive resource consumption on the GitLab server, leading to denial of service conditions.

Mitigation

Upgrade GitLab to version 17.10.7, 17.11.3, 18.0.1 or later. If immediate upgrade is not possible, implement rate limiting and monitoring for unusual resource consumption patterns from authenticated users.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

0.49%
Probability of exploitation in next 30 days
41.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE